docs(security): point to the shared security page and keep MAX specifics - #387
Merged
Merged
Conversation
The generic parts — the local store, the send guard, agent boundaries, other people's text, what others on the machine see, personal use under GDPR — now live on the shared page at wirecat.dev/ru/docs/security, which tg and max both link. This page keeps what only MAX has: the token and MAX_TOKEN, the bot token, max serve's checks, the bot guard keys, MAX's endpoints and client imitation, MAX's terms, browser login, the unofficial protocol and what to do when a token leaks. Adds SECURITY.md with the private reporting channels, and corrects docs/dev/ARCHITECTURE.md §1 and §17: max now plugs into cli-messaging through maxMessenger and maxAdapter, and MCP tools follow permissions. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Task
The tg and max security pages repeated the same shared design. The owner asked for one shared security page on wirecat.dev, with each tool page keeping only its own details and linking to it. The owner also asked for a private way to report a vulnerability.
Why
SECURITY.md.What
docs/security.md: a lead paragraph links https://wirecat.dev/ru/docs/security. The generic sections are cut to one line plus a link each: the summary, the guard explanation, "what it cannot hold", other people's text, what others on the machine see, the GDPR part of personal use, and the lost-computer case.MAX_TOKENand the bot token; the disk table;max servechecks; the bot guard keys; the MAX network table and client imitation; MAX's terms; browser login; the unofficial protocol; a leaked token; 152-ФЗ.SECURITY.md: hello@wirecat.dev, or GitHub private vulnerability reporting.docs/dev/ARCHITECTURE.md§1 and §17 are corrected in place:maxMessenger/maxAdapter(feat(messenger): the MAX Messenger for cli-messaging's shared commands #260, refactor(mcp): use shared services and account-scoped archive #335);permissions(feat(permissions): complete MAX P7 config, guards and MCP cutover #382).The shared page lands in leemour/cli-docs on branch
docs/architecture. Its links show up on the site with the next max release.Testing
pnpm lint,pnpm typecheck,pnpm test(1371 passed),pnpm docs:check,pnpm parity:check: all pass.🤖 Generated with Claude Code