LLeMbas CLI 1.0.0
ci / check (push) Waiting to run

The first public release of LLeMbas CLI: a terminal coding agent and project manager for any LLM
API, with permission modes, git snapshots, memory and skills, knowledge bases, MCP, voice, and a
link to a LLeMbas instance whose web UI can work its sessions too. Signed Linux binaries for x64
and arm64.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
HomerandClaude Opus 5.5 committed 2026-10-09 21:59:03 +00:00
commit f9bad01ed7
355 files changed
+47028

No files matched your search

+170
View File
@@ -0,0 +1,170 @@
{
"about": "How many words make the human-meaningful prefix of a command, for an \"always allow\" pattern: `git commit -m x` → `git commit *`. The longest listed prefix wins; options never count; a command not listed is its first word.",
"source": "OpenCode packages/opencode/src/permission/arity.ts (MIT, © 2025 opencode).",
"exact_only": [
"sudo",
"doas",
"env",
"xargs",
"sh",
"bash",
"zsh",
"dash",
"ksh",
"fish",
"nice",
"timeout",
"nohup",
"exec",
"command",
"builtin",
"time",
"stdbuf",
"ionice",
"setsid",
"watch",
"find",
"busybox",
"eval",
"source"
],
"exact_only_about": "Commands that run another command (or can): approved only exactly, never with *.",
"arity": {
"cat": 1,
"cd": 1,
"chmod": 1,
"chown": 1,
"cp": 1,
"echo": 1,
"env": 1,
"export": 1,
"grep": 1,
"kill": 1,
"killall": 1,
"ln": 1,
"ls": 1,
"mkdir": 1,
"mv": 1,
"ps": 1,
"pwd": 1,
"rm": 1,
"rmdir": 1,
"sleep": 1,
"source": 1,
"tail": 1,
"touch": 1,
"unset": 1,
"which": 1,
"aws": 3,
"az": 3,
"bazel": 2,
"brew": 2,
"bun": 2,
"bun run": 3,
"bun x": 3,
"cargo": 2,
"cargo add": 3,
"cargo run": 3,
"cdk": 2,
"cf": 2,
"cmake": 2,
"composer": 2,
"consul": 2,
"consul kv": 3,
"crictl": 2,
"deno": 2,
"deno task": 3,
"doctl": 3,
"docker": 2,
"docker builder": 3,
"docker compose": 3,
"docker container": 3,
"docker image": 3,
"docker network": 3,
"docker volume": 3,
"eksctl": 2,
"eksctl create": 3,
"firebase": 2,
"flyctl": 2,
"gcloud": 3,
"gh": 3,
"git": 2,
"git config": 3,
"git remote": 3,
"git stash": 3,
"go": 2,
"gradle": 2,
"helm": 2,
"heroku": 2,
"hugo": 2,
"ip": 2,
"ip addr": 3,
"ip link": 3,
"ip netns": 3,
"ip route": 3,
"kind": 2,
"kind create": 3,
"kubectl": 2,
"kubectl kustomize": 3,
"kubectl rollout": 3,
"kustomize": 2,
"make": 2,
"mc": 2,
"mc admin": 3,
"minikube": 2,
"mongosh": 2,
"mysql": 2,
"mvn": 2,
"ng": 2,
"npm": 2,
"npm exec": 3,
"npm init": 3,
"npm run": 3,
"npm view": 3,
"nvm": 2,
"nx": 2,
"openssl": 2,
"openssl req": 3,
"openssl x509": 3,
"pip": 2,
"pipenv": 2,
"pnpm": 2,
"pnpm dlx": 3,
"pnpm exec": 3,
"pnpm run": 3,
"poetry": 2,
"podman": 2,
"podman container": 3,
"podman image": 3,
"psql": 2,
"pulumi": 2,
"pulumi stack": 3,
"pyenv": 2,
"python": 2,
"rake": 2,
"rbenv": 2,
"redis-cli": 2,
"rustup": 2,
"serverless": 2,
"sfdx": 3,
"skaffold": 2,
"sls": 2,
"sst": 2,
"swift": 2,
"systemctl": 2,
"terraform": 2,
"terraform workspace": 3,
"tmux": 2,
"turbo": 2,
"ufw": 2,
"vault": 2,
"vault auth": 3,
"vault kv": 3,
"vercel": 2,
"volta": 2,
"wp": 2,
"yarn": 2,
"yarn dlx": 3,
"yarn run": 3
}
}
+76
View File
@@ -0,0 +1,76 @@
{
"about": "The rules every session starts from, before the user's own. Keys are permission keys (a tool's access), values an action or a map of pattern → action; for a pattern the last matching rule wins, across patterns the strictest.",
"rules": {
"*": "ask",
"read": {
"*": "allow",
"*.env": "ask",
"*.env.*": "ask",
"*.env.example": "allow"
},
"glob": "allow",
"grep": "allow",
"list": "allow",
"ask_user": "allow",
"plan_submit": "allow",
"task": "allow",
"tasks": "allow",
"decisions": "allow",
"todo": "allow",
"bash_output": "allow",
"bash_kill": "allow",
"web_search": "allow",
"memory": "allow",
"session_search": "allow",
"notes": "allow",
"knowledge": "allow",
"skills": "allow",
"skill_manage": "ask",
"settings": {
"*": "ask",
"list": "allow",
"get *": "allow"
},
"web_fetch": {
"*": "allow",
"private:*": "ask"
},
"external_directory": "ask",
"bash": {
"*": "ask",
"git status *": "allow",
"git diff *": "allow",
"git log *": "allow",
"git show *": "allow",
"git branch": "allow",
"git branch --list *": "allow",
"git branch -a": "allow",
"git branch -v": "allow",
"git branch -vv": "allow",
"git branch -av": "allow",
"git rev-parse *": "allow",
"git blame *": "allow",
"ls *": "allow",
"pwd": "allow",
"cat *": "allow",
"head *": "allow",
"tail *": "allow",
"wc *": "allow",
"which *": "allow",
"rg *": "allow",
"grep *": "allow",
"file *": "allow",
"tree *": "allow",
"git diff *--output*": "ask",
"git log *--output*": "ask",
"git show *--output*": "ask",
"git branch --list *-*": "ask",
"rg *--pre*": "ask",
"rg *--hostname-bin*": "ask",
"rg *--search-zip*": "ask",
"tree *-o*": "ask",
"tree *-R*": "ask",
"file *-C*": "ask"
}
}
}
+222
View File
@@ -0,0 +1,222 @@
{
"about": "The floor: commands refused in every mode, auto included. A command line is checked raw, and each simple command again in a plain spelling (see `plain`). Patterns are regular expressions with the flags given, written to read the same in JavaScript and Python re.",
"source": "Patterns ported from Hermes Agent tools/approval_detection.py HARDLINE_PATTERNS (MIT, © 2025 Nous Research), plus the CLI's own (force-push-main, find-delete-system).",
"flags": "is",
"rules": [
{
"id": "rm-root",
"description": "recursive delete of the root filesystem",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*rm\\s+(?:-\\S*\\s+)*(?:[\"'](?:\\/(?:(?:\\.\\.?)?\\/)*(?:\\.\\.?)?\\**|\\/ \\*)[\"']|(?:\\/(?:(?:\\.\\.?)?\\/)*(?:\\.\\.?)?\\**|\\/ \\*)(?:\\s|$|[)\\`;|&]))"
},
{
"id": "rm-system",
"description": "recursive delete of a system directory",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*rm\\s+(?:-\\S*\\s+)*(?:[\"'](?:\\/home|\\/home\\/\\*|\\/root|\\/root\\/\\*|\\/etc|\\/etc\\/\\*|\\/usr|\\/usr\\/\\*|\\/var|\\/var\\/\\*|\\/bin|\\/bin\\/\\*|\\/sbin|\\/sbin\\/\\*|\\/boot|\\/boot\\/\\*|\\/lib|\\/lib\\/\\*)[\"']|(?:\\/home|\\/home\\/\\*|\\/root|\\/root\\/\\*|\\/etc|\\/etc\\/\\*|\\/usr|\\/usr\\/\\*|\\/var|\\/var\\/\\*|\\/bin|\\/bin\\/\\*|\\/sbin|\\/sbin\\/\\*|\\/boot|\\/boot\\/\\*|\\/lib|\\/lib\\/\\*)(?:\\s|$|[)\\`;|&]))"
},
{
"id": "rm-home",
"description": "recursive delete of the home directory",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*rm\\s+(?:-\\S*\\s+)*(?:[\"'](?:(?:~|\\$\\{?HOME\\}?)(?:\\/?|\\/\\*)?)[\"']|(?:(?:~|\\$\\{?HOME\\}?)(?:\\/?|\\/\\*)?)(?:\\s|$|[)\\`;|&]))"
},
{
"id": "mkfs",
"description": "format a filesystem",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*mkfs(?:\\.[a-z0-9]+)?\\b"
},
{
"id": "dd-device",
"description": "dd to a raw block device",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*dd\\b[^\\n]*\\bof=\\/dev\\/(?:sd|nvme|hd|mmcblk|vd|xvd)[a-z0-9]*"
},
{
"id": "redirect-device",
"description": "redirect to a raw block device",
"pattern": ">\\s*\\/dev\\/(?:sd|nvme|hd|mmcblk|vd|xvd)[a-z0-9]*\\b"
},
{
"id": "fork-bomb",
"description": "fork bomb",
"pattern": ":\\(\\)\\s*\\{\\s*:\\s*\\|\\s*:\\s*&\\s*\\}\\s*;\\s*:"
},
{
"id": "kill-all",
"description": "kill every process",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*kill\\s+(?:-\\S+\\s+)*-1\\b"
},
{
"id": "shutdown",
"description": "shut down or reboot the machine",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*(?:shutdown|reboot|halt|poweroff)\\b"
},
{
"id": "init-06",
"description": "init 0/6",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*(?:tel)?init\\s+[06]\\b"
},
{
"id": "systemctl-power",
"description": "systemctl poweroff/reboot",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*systemctl\\s+(?:poweroff|reboot|halt|kexec)\\b"
},
{
"id": "force-push-main",
"description": "force-push to main/master",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*git\\s+push\\b(?=[^\\n;&|]*(?:\\s--force\\b|\\s-[a-zA-Z]*f[a-zA-Z]*\\b|\\s--force-with-lease\\b|\\s\\+))[^\\n;&|]*\\b(?:main|master)\\b"
},
{
"id": "find-delete-system",
"description": "find deleting under the root, the home or a system directory",
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*find\\s+(?:-[HLP]\\s+)*[\"']?(?:\\/|~|\\$\\{?HOME\\}?|\\/home|\\/home\\/\\*|\\/root|\\/root\\/\\*|\\/etc|\\/etc\\/\\*|\\/usr|\\/usr\\/\\*|\\/var|\\/var\\/\\*|\\/bin|\\/bin\\/\\*|\\/sbin|\\/sbin\\/\\*|\\/boot|\\/boot\\/\\*|\\/lib|\\/lib\\/\\*)[\"']?\\s[^\\n;&|]*(?:-delete\\b|-exec(?:dir)?\\s+rm\\b)"
}
],
"protected_paths": [
{
"path": "~/.ssh",
"scope": "shared"
},
{
"path": "~/.gnupg",
"scope": "shared"
},
{
"path": "<config>/connections.yaml",
"label": "connections.yaml",
"scope": "cli"
}
],
"plain": {
"about": "How a simple command is spelled plainly before the rules are checked again: leading keywords and VAR= assignments dropped; wrapper programs and their options taken off (an option listed for a wrapper takes a value); `timeout` also drops its duration; a shell's -c argument read as its own line; git's global options dropped; quotes, escapes and program paths removed; paths normalised (~ for the home directory).",
"wrappers": {
"sudo": [
"-u",
"-g",
"-h",
"-p",
"-C",
"-D",
"-r",
"-t",
"-U",
"-T",
"--user",
"--group",
"--host",
"--prompt",
"--chdir",
"--close-from",
"--role",
"--type",
"--other-user",
"--command-timeout"
],
"doas": [
"-u",
"-C"
],
"env": [
"-u",
"-C",
"--unset",
"--chdir"
],
"nice": [
"-n",
"--adjustment"
],
"timeout": [
"-s",
"-k",
"--signal",
"--kill-after"
],
"stdbuf": [
"-i",
"-o",
"-e",
"--input",
"--output",
"--error"
],
"ionice": [
"-c",
"-n",
"-p",
"-P",
"-u",
"--class",
"--classdata"
],
"xargs": [
"-a",
"-d",
"-E",
"-e",
"-I",
"-i",
"-L",
"-l",
"-n",
"-P",
"-s",
"--arg-file",
"--delimiter",
"--eof",
"--replace",
"--max-lines",
"--max-args",
"--max-procs",
"--max-chars"
],
"exec": [
"-a"
],
"nohup": [],
"setsid": [],
"command": [],
"builtin": [],
"time": [
"-f",
"-o",
"--format",
"--output"
],
"chronic": [],
"unbuffer": [],
"busybox": []
},
"keywords": [
"{",
"}",
"(",
")",
"!",
"if",
"then",
"else",
"elif",
"do",
"while",
"until",
"time"
],
"shells": [
"sh",
"bash",
"zsh",
"dash",
"ksh",
"mksh",
"fish",
"ash"
],
"git_value_options": [
"-C",
"-c",
"--git-dir",
"--work-tree",
"--namespace",
"--exec-path",
"--config-env"
]
}
}
+38
View File
@@ -0,0 +1,38 @@
{
"about": "The four permission modes, as what each does with a call of each risk class once the hardline and the rules have spoken. `rules` means the permission rules decide (defaults.json, then the user's, then a trusted project's, then this session's approvals); anything the rules do not allow is asked. A deny from the rules or the hardline is final in every mode.",
"order": ["auto", "edit", "manual", "plan"],
"order_about": "Loosest first. A project or a subagent may make the mode stricter, never looser; switching to a looser mode is always asked.",
"aliases": { "unrestricted": "auto" },
"floor": "The hardline (hardline.json) and the protected paths are refused in every mode, auto included.",
"modes": {
"manual": {
"summary": "Everything not already allowed is asked.",
"read": "rules",
"write": "rules",
"execute": "rules",
"interact": "rules"
},
"edit": {
"summary": "Reading and changing files inside the project runs without asking; commands, and anything outside the project, follow the rules.",
"read": "allow inside the project, unless a rule written for that tool says ask (reading .env still asks); outside the project: rules",
"write": "allow inside the project, except git's own files (.git/) and the agent's own configuration in the project (config, agents, commands, skills); outside: rules",
"execute": "rules",
"interact": "rules"
},
"auto": {
"summary": "Nothing is asked. The hardline still refuses.",
"read": "allow",
"write": "allow",
"execute": "allow",
"interact": "allow"
},
"plan": {
"summary": "Investigate and write a plan; change nothing else.",
"read": "rules",
"write": "allow only for files under the plans directory; anything else is refused",
"execute": "only what the rules already allow; anything else is refused",
"interact": "rules"
}
},
"unattended": "With nobody to answer, whatever a mode would ask is refused instead, and the model is told so up front (prompts/modes/unattended.md)."
}