lcode is young; security fixes go into the latest release on main.
| Version | Supported |
|---|---|
| 0.2.x (latest) | ✅ |
| older | ❌ |
Please don't open a public issue for security problems. Report them privately through GitHub's private vulnerability reporting. Include what you found, how to reproduce it, and the impact you expect.
You can expect an acknowledgement within 3 days and a status update within 10 days. Once a fix is released you'll be credited in the advisory unless you prefer otherwise.
lcode runs a language model on your machine and lets it read files and run shell commands as your user, in your working directory. It is not a sandbox. Keep in mind:
- In the default
askmode, every file edit and every shell command that isn't on the read-only allowlist (ls,cat,grep,git status, …) is shown to you and needs your approval.auto-editskips approval for edits;yoloskips all approval — use it only with the sandbox or in disposable environments (a VM, a throwaway clone). - The optional sandbox (
sandbox = "docker"or"podman", orlcode --sandbox) runs shell commands in a container that sees only the project folder, as your user, without network access unless allowed. The file tools are then limited to the project too. It doesn't cover web or MCP tools, the project folder itself stays writable, and a container shares the host kernel; see https://nasser1941.github.io/lcode/sandbox/ for its limits. - Content the model reads (files, command output, search results and web pages) can contain prompt injections that try to make it run harmful commands. lcode marks web content as untrusted, but review commands before approving them.
- The model runs on the Ollama server you configure (default
http://localhost:11434); if you pointollama_hostat a remote server, your prompts and code go to that server. lcode sends no telemetry. - With web access on (the default), search queries go to the configured search provider and fetched
pages are downloaded from their websites. The model writes the queries, so they can contain names or
snippets from your code. Use
web = askto approve each search, orweb = off/--no-webto keep everything local. - MCP servers you add run as your user (local servers) or act on your accounts (remote servers).
Every MCP tool call needs your approval unless you're in
yolomode or listed the tool underallow. A project's.mcp.jsonis only used after you approve it, and again after it changes. MCP tool results can contain prompt injections, like web pages. Tokens you enter are stored in~/.config/lcode/mcp.jsonand sign-in tokens in~/.local/state/lcode/mcp-auth/, both readable only by you. - Sessions (including file contents the model read) are stored in
~/.local/state/lcode/sessions. Checkpoints for/undokeep copies of your project's files (except ignored ones) in~/.local/state/lcode/checkpointsfor 14 days; turn them off withcheckpoints = false.
Reports about bypassing the permission prompts, the read-only allowlist, or data leaving the machine unexpectedly are especially welcome.