Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Security

Please report a security problem privately — never in a public issue or the support chat:

- by email: [hello@wirecat.dev](mailto:hello@wirecat.dev);
- or through [GitHub's private vulnerability reporting](https://github.com/leemour/max-cli/security/advisories/new).

Say what you saw, how to repeat it, and the version (`max --version`). Never send a token, a
session or anyone's messages.

What the tool keeps on your computer and what stops an agent from sending:
[wirecat.dev/en/docs/security](https://wirecat.dev/en/docs/security), and the MAX details in
[docs/security.md](docs/security.md).
21 changes: 21 additions & 0 deletions docs/dev/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,18 @@ only the event lines.
(the run directory and the event format: cli-messaging's, T6 item 3c)
```

**Correction 2026-10-04:** the diagram above is the personal account's own half. Since #260 and T6 (#330–#382)
max also plugs into `@leemour/cli-messaging`: `src/messenger.ts` describes MAX once as a `Messenger`
(`maxMessenger` — provider, paging, the guard, permissions), and `src/adapter/max-adapter.ts`
(`maxAdapter`) wraps `MaxClient` behind cli-messaging's `MessengerAdapter` port, translating MAX's
models into the shared domain types. `src/program.ts` registers cli-messaging's shared commands —
`store`, `conversations`, `polls`, `reactions`, `inbox`, `review`, and `chats mark-read` among `chats`
— beside max's own; they reach MAX only through that adapter, and read and write the shared store
(`~/.local/share/cli-messaging/messages.db`), not a cache of max's own. So the path is now
commands → cli-messaging services → `maxAdapter` → `MaxClient` → protocol; `MaxClient` stays the
only code that knows the wire. `src/adapter/contract.test.ts` runs cli-messaging's contract cases over
the adapter.

- Commands are resource + action (`NEED-48`); the diagram matches `max --help`. Adding an operation:
§12.
- [`@leemour/cli-core`](https://github.com/leemour/cli-core) supplies output streams, renderer,
Expand Down Expand Up @@ -507,6 +519,15 @@ tool calls `MaxClient`, and the Biome rule that keeps commands off `protocol/`,
`generated/` covers `src/mcp/` too. The context comes from `contextFor` — the same settings,
keyring, deadline and run record as a command, built from flags instead of argv.

**Correction 2026-10-04:** the server is still max's own (`src/mcp/server.ts`, `MaxSession`), but most
tools now run cli-messaging's services over the held client: `withShared` (`src/mcp/shared.ts`) builds
`servicesFor(…)` over `maxAdapter(client)` and the shared store, so a tool and its command run the same
method. Which tools exist is decided by the profile's `permissions` (P7, #382), not by flags:
`registerTools` (`src/mcp/tools.ts`) leaves out a tool whose level is `deny`, a write tool whose level
is `readonly`, and shows a form for `ask` or with `--confirm-send`. `--allow-send`, `--allow-mark-read`,
`--allow-delete` and `--allow-moderate` are accepted with a deprecation note and grant nothing
(`src/commands/mcp.ts`). The "sending is absent without `--allow-send`" bullet below is superseded.

- **One connection per agent session, never for long** (`NEED-152`): `MaxSession` logs in on the
first call and keeps the client; it drops it after 2 minutes idle, 5 minutes after the login
whatever the traffic (the chat list is the login's snapshot), after any error that may have been
Expand Down
Loading
Loading