The first public release of LLeMbas CLI: a terminal coding agent and project manager for any LLM API, with permission modes, git snapshots, memory and skills, knowledge bases, MCP, voice, and a link to a LLeMbas instance whose web UI can work its sessions too. Signed Linux binaries for x64 and arm64. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
355 files changed
+47028
No files matched your search
@@ -0,0 +1,170 @@
|
||||
{
|
||||
"about": "How many words make the human-meaningful prefix of a command, for an \"always allow\" pattern: `git commit -m x` → `git commit *`. The longest listed prefix wins; options never count; a command not listed is its first word.",
|
||||
"source": "OpenCode packages/opencode/src/permission/arity.ts (MIT, © 2025 opencode).",
|
||||
"exact_only": [
|
||||
"sudo",
|
||||
"doas",
|
||||
"env",
|
||||
"xargs",
|
||||
"sh",
|
||||
"bash",
|
||||
"zsh",
|
||||
"dash",
|
||||
"ksh",
|
||||
"fish",
|
||||
"nice",
|
||||
"timeout",
|
||||
"nohup",
|
||||
"exec",
|
||||
"command",
|
||||
"builtin",
|
||||
"time",
|
||||
"stdbuf",
|
||||
"ionice",
|
||||
"setsid",
|
||||
"watch",
|
||||
"find",
|
||||
"busybox",
|
||||
"eval",
|
||||
"source"
|
||||
],
|
||||
"exact_only_about": "Commands that run another command (or can): approved only exactly, never with *.",
|
||||
"arity": {
|
||||
"cat": 1,
|
||||
"cd": 1,
|
||||
"chmod": 1,
|
||||
"chown": 1,
|
||||
"cp": 1,
|
||||
"echo": 1,
|
||||
"env": 1,
|
||||
"export": 1,
|
||||
"grep": 1,
|
||||
"kill": 1,
|
||||
"killall": 1,
|
||||
"ln": 1,
|
||||
"ls": 1,
|
||||
"mkdir": 1,
|
||||
"mv": 1,
|
||||
"ps": 1,
|
||||
"pwd": 1,
|
||||
"rm": 1,
|
||||
"rmdir": 1,
|
||||
"sleep": 1,
|
||||
"source": 1,
|
||||
"tail": 1,
|
||||
"touch": 1,
|
||||
"unset": 1,
|
||||
"which": 1,
|
||||
"aws": 3,
|
||||
"az": 3,
|
||||
"bazel": 2,
|
||||
"brew": 2,
|
||||
"bun": 2,
|
||||
"bun run": 3,
|
||||
"bun x": 3,
|
||||
"cargo": 2,
|
||||
"cargo add": 3,
|
||||
"cargo run": 3,
|
||||
"cdk": 2,
|
||||
"cf": 2,
|
||||
"cmake": 2,
|
||||
"composer": 2,
|
||||
"consul": 2,
|
||||
"consul kv": 3,
|
||||
"crictl": 2,
|
||||
"deno": 2,
|
||||
"deno task": 3,
|
||||
"doctl": 3,
|
||||
"docker": 2,
|
||||
"docker builder": 3,
|
||||
"docker compose": 3,
|
||||
"docker container": 3,
|
||||
"docker image": 3,
|
||||
"docker network": 3,
|
||||
"docker volume": 3,
|
||||
"eksctl": 2,
|
||||
"eksctl create": 3,
|
||||
"firebase": 2,
|
||||
"flyctl": 2,
|
||||
"gcloud": 3,
|
||||
"gh": 3,
|
||||
"git": 2,
|
||||
"git config": 3,
|
||||
"git remote": 3,
|
||||
"git stash": 3,
|
||||
"go": 2,
|
||||
"gradle": 2,
|
||||
"helm": 2,
|
||||
"heroku": 2,
|
||||
"hugo": 2,
|
||||
"ip": 2,
|
||||
"ip addr": 3,
|
||||
"ip link": 3,
|
||||
"ip netns": 3,
|
||||
"ip route": 3,
|
||||
"kind": 2,
|
||||
"kind create": 3,
|
||||
"kubectl": 2,
|
||||
"kubectl kustomize": 3,
|
||||
"kubectl rollout": 3,
|
||||
"kustomize": 2,
|
||||
"make": 2,
|
||||
"mc": 2,
|
||||
"mc admin": 3,
|
||||
"minikube": 2,
|
||||
"mongosh": 2,
|
||||
"mysql": 2,
|
||||
"mvn": 2,
|
||||
"ng": 2,
|
||||
"npm": 2,
|
||||
"npm exec": 3,
|
||||
"npm init": 3,
|
||||
"npm run": 3,
|
||||
"npm view": 3,
|
||||
"nvm": 2,
|
||||
"nx": 2,
|
||||
"openssl": 2,
|
||||
"openssl req": 3,
|
||||
"openssl x509": 3,
|
||||
"pip": 2,
|
||||
"pipenv": 2,
|
||||
"pnpm": 2,
|
||||
"pnpm dlx": 3,
|
||||
"pnpm exec": 3,
|
||||
"pnpm run": 3,
|
||||
"poetry": 2,
|
||||
"podman": 2,
|
||||
"podman container": 3,
|
||||
"podman image": 3,
|
||||
"psql": 2,
|
||||
"pulumi": 2,
|
||||
"pulumi stack": 3,
|
||||
"pyenv": 2,
|
||||
"python": 2,
|
||||
"rake": 2,
|
||||
"rbenv": 2,
|
||||
"redis-cli": 2,
|
||||
"rustup": 2,
|
||||
"serverless": 2,
|
||||
"sfdx": 3,
|
||||
"skaffold": 2,
|
||||
"sls": 2,
|
||||
"sst": 2,
|
||||
"swift": 2,
|
||||
"systemctl": 2,
|
||||
"terraform": 2,
|
||||
"terraform workspace": 3,
|
||||
"tmux": 2,
|
||||
"turbo": 2,
|
||||
"ufw": 2,
|
||||
"vault": 2,
|
||||
"vault auth": 3,
|
||||
"vault kv": 3,
|
||||
"vercel": 2,
|
||||
"volta": 2,
|
||||
"wp": 2,
|
||||
"yarn": 2,
|
||||
"yarn dlx": 3,
|
||||
"yarn run": 3
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,76 @@
|
||||
{
|
||||
"about": "The rules every session starts from, before the user's own. Keys are permission keys (a tool's access), values an action or a map of pattern → action; for a pattern the last matching rule wins, across patterns the strictest.",
|
||||
"rules": {
|
||||
"*": "ask",
|
||||
"read": {
|
||||
"*": "allow",
|
||||
"*.env": "ask",
|
||||
"*.env.*": "ask",
|
||||
"*.env.example": "allow"
|
||||
},
|
||||
"glob": "allow",
|
||||
"grep": "allow",
|
||||
"list": "allow",
|
||||
"ask_user": "allow",
|
||||
"plan_submit": "allow",
|
||||
"task": "allow",
|
||||
"tasks": "allow",
|
||||
"decisions": "allow",
|
||||
"todo": "allow",
|
||||
"bash_output": "allow",
|
||||
"bash_kill": "allow",
|
||||
"web_search": "allow",
|
||||
"memory": "allow",
|
||||
"session_search": "allow",
|
||||
"notes": "allow",
|
||||
"knowledge": "allow",
|
||||
"skills": "allow",
|
||||
"skill_manage": "ask",
|
||||
"settings": {
|
||||
"*": "ask",
|
||||
"list": "allow",
|
||||
"get *": "allow"
|
||||
},
|
||||
"web_fetch": {
|
||||
"*": "allow",
|
||||
"private:*": "ask"
|
||||
},
|
||||
"external_directory": "ask",
|
||||
"bash": {
|
||||
"*": "ask",
|
||||
"git status *": "allow",
|
||||
"git diff *": "allow",
|
||||
"git log *": "allow",
|
||||
"git show *": "allow",
|
||||
"git branch": "allow",
|
||||
"git branch --list *": "allow",
|
||||
"git branch -a": "allow",
|
||||
"git branch -v": "allow",
|
||||
"git branch -vv": "allow",
|
||||
"git branch -av": "allow",
|
||||
"git rev-parse *": "allow",
|
||||
"git blame *": "allow",
|
||||
"ls *": "allow",
|
||||
"pwd": "allow",
|
||||
"cat *": "allow",
|
||||
"head *": "allow",
|
||||
"tail *": "allow",
|
||||
"wc *": "allow",
|
||||
"which *": "allow",
|
||||
"rg *": "allow",
|
||||
"grep *": "allow",
|
||||
"file *": "allow",
|
||||
"tree *": "allow",
|
||||
"git diff *--output*": "ask",
|
||||
"git log *--output*": "ask",
|
||||
"git show *--output*": "ask",
|
||||
"git branch --list *-*": "ask",
|
||||
"rg *--pre*": "ask",
|
||||
"rg *--hostname-bin*": "ask",
|
||||
"rg *--search-zip*": "ask",
|
||||
"tree *-o*": "ask",
|
||||
"tree *-R*": "ask",
|
||||
"file *-C*": "ask"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,222 @@
|
||||
{
|
||||
"about": "The floor: commands refused in every mode, auto included. A command line is checked raw, and each simple command again in a plain spelling (see `plain`). Patterns are regular expressions with the flags given, written to read the same in JavaScript and Python re.",
|
||||
"source": "Patterns ported from Hermes Agent tools/approval_detection.py HARDLINE_PATTERNS (MIT, © 2025 Nous Research), plus the CLI's own (force-push-main, find-delete-system).",
|
||||
"flags": "is",
|
||||
"rules": [
|
||||
{
|
||||
"id": "rm-root",
|
||||
"description": "recursive delete of the root filesystem",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*rm\\s+(?:-\\S*\\s+)*(?:[\"'](?:\\/(?:(?:\\.\\.?)?\\/)*(?:\\.\\.?)?\\**|\\/ \\*)[\"']|(?:\\/(?:(?:\\.\\.?)?\\/)*(?:\\.\\.?)?\\**|\\/ \\*)(?:\\s|$|[)\\`;|&]))"
|
||||
},
|
||||
{
|
||||
"id": "rm-system",
|
||||
"description": "recursive delete of a system directory",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*rm\\s+(?:-\\S*\\s+)*(?:[\"'](?:\\/home|\\/home\\/\\*|\\/root|\\/root\\/\\*|\\/etc|\\/etc\\/\\*|\\/usr|\\/usr\\/\\*|\\/var|\\/var\\/\\*|\\/bin|\\/bin\\/\\*|\\/sbin|\\/sbin\\/\\*|\\/boot|\\/boot\\/\\*|\\/lib|\\/lib\\/\\*)[\"']|(?:\\/home|\\/home\\/\\*|\\/root|\\/root\\/\\*|\\/etc|\\/etc\\/\\*|\\/usr|\\/usr\\/\\*|\\/var|\\/var\\/\\*|\\/bin|\\/bin\\/\\*|\\/sbin|\\/sbin\\/\\*|\\/boot|\\/boot\\/\\*|\\/lib|\\/lib\\/\\*)(?:\\s|$|[)\\`;|&]))"
|
||||
},
|
||||
{
|
||||
"id": "rm-home",
|
||||
"description": "recursive delete of the home directory",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*rm\\s+(?:-\\S*\\s+)*(?:[\"'](?:(?:~|\\$\\{?HOME\\}?)(?:\\/?|\\/\\*)?)[\"']|(?:(?:~|\\$\\{?HOME\\}?)(?:\\/?|\\/\\*)?)(?:\\s|$|[)\\`;|&]))"
|
||||
},
|
||||
{
|
||||
"id": "mkfs",
|
||||
"description": "format a filesystem",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*mkfs(?:\\.[a-z0-9]+)?\\b"
|
||||
},
|
||||
{
|
||||
"id": "dd-device",
|
||||
"description": "dd to a raw block device",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*dd\\b[^\\n]*\\bof=\\/dev\\/(?:sd|nvme|hd|mmcblk|vd|xvd)[a-z0-9]*"
|
||||
},
|
||||
{
|
||||
"id": "redirect-device",
|
||||
"description": "redirect to a raw block device",
|
||||
"pattern": ">\\s*\\/dev\\/(?:sd|nvme|hd|mmcblk|vd|xvd)[a-z0-9]*\\b"
|
||||
},
|
||||
{
|
||||
"id": "fork-bomb",
|
||||
"description": "fork bomb",
|
||||
"pattern": ":\\(\\)\\s*\\{\\s*:\\s*\\|\\s*:\\s*&\\s*\\}\\s*;\\s*:"
|
||||
},
|
||||
{
|
||||
"id": "kill-all",
|
||||
"description": "kill every process",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*kill\\s+(?:-\\S+\\s+)*-1\\b"
|
||||
},
|
||||
{
|
||||
"id": "shutdown",
|
||||
"description": "shut down or reboot the machine",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*(?:shutdown|reboot|halt|poweroff)\\b"
|
||||
},
|
||||
{
|
||||
"id": "init-06",
|
||||
"description": "init 0/6",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*(?:tel)?init\\s+[06]\\b"
|
||||
},
|
||||
{
|
||||
"id": "systemctl-power",
|
||||
"description": "systemctl poweroff/reboot",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*systemctl\\s+(?:poweroff|reboot|halt|kexec)\\b"
|
||||
},
|
||||
{
|
||||
"id": "force-push-main",
|
||||
"description": "force-push to main/master",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*git\\s+push\\b(?=[^\\n;&|]*(?:\\s--force\\b|\\s-[a-zA-Z]*f[a-zA-Z]*\\b|\\s--force-with-lease\\b|\\s\\+))[^\\n;&|]*\\b(?:main|master)\\b"
|
||||
},
|
||||
{
|
||||
"id": "find-delete-system",
|
||||
"description": "find deleting under the root, the home or a system directory",
|
||||
"pattern": "(?:^|[\\n\\`;&|(]|\\$\\()\\s*(?:sudo\\s+(?:-\\S+\\s+)*)?(?:env\\s+(?:\\w+=\\S*\\s+)*)?(?:(?:exec|nohup|setsid|time|command)\\s+)*\\s*find\\s+(?:-[HLP]\\s+)*[\"']?(?:\\/|~|\\$\\{?HOME\\}?|\\/home|\\/home\\/\\*|\\/root|\\/root\\/\\*|\\/etc|\\/etc\\/\\*|\\/usr|\\/usr\\/\\*|\\/var|\\/var\\/\\*|\\/bin|\\/bin\\/\\*|\\/sbin|\\/sbin\\/\\*|\\/boot|\\/boot\\/\\*|\\/lib|\\/lib\\/\\*)[\"']?\\s[^\\n;&|]*(?:-delete\\b|-exec(?:dir)?\\s+rm\\b)"
|
||||
}
|
||||
],
|
||||
"protected_paths": [
|
||||
{
|
||||
"path": "~/.ssh",
|
||||
"scope": "shared"
|
||||
},
|
||||
{
|
||||
"path": "~/.gnupg",
|
||||
"scope": "shared"
|
||||
},
|
||||
{
|
||||
"path": "<config>/connections.yaml",
|
||||
"label": "connections.yaml",
|
||||
"scope": "cli"
|
||||
}
|
||||
],
|
||||
"plain": {
|
||||
"about": "How a simple command is spelled plainly before the rules are checked again: leading keywords and VAR= assignments dropped; wrapper programs and their options taken off (an option listed for a wrapper takes a value); `timeout` also drops its duration; a shell's -c argument read as its own line; git's global options dropped; quotes, escapes and program paths removed; paths normalised (~ for the home directory).",
|
||||
"wrappers": {
|
||||
"sudo": [
|
||||
"-u",
|
||||
"-g",
|
||||
"-h",
|
||||
"-p",
|
||||
"-C",
|
||||
"-D",
|
||||
"-r",
|
||||
"-t",
|
||||
"-U",
|
||||
"-T",
|
||||
"--user",
|
||||
"--group",
|
||||
"--host",
|
||||
"--prompt",
|
||||
"--chdir",
|
||||
"--close-from",
|
||||
"--role",
|
||||
"--type",
|
||||
"--other-user",
|
||||
"--command-timeout"
|
||||
],
|
||||
"doas": [
|
||||
"-u",
|
||||
"-C"
|
||||
],
|
||||
"env": [
|
||||
"-u",
|
||||
"-C",
|
||||
"--unset",
|
||||
"--chdir"
|
||||
],
|
||||
"nice": [
|
||||
"-n",
|
||||
"--adjustment"
|
||||
],
|
||||
"timeout": [
|
||||
"-s",
|
||||
"-k",
|
||||
"--signal",
|
||||
"--kill-after"
|
||||
],
|
||||
"stdbuf": [
|
||||
"-i",
|
||||
"-o",
|
||||
"-e",
|
||||
"--input",
|
||||
"--output",
|
||||
"--error"
|
||||
],
|
||||
"ionice": [
|
||||
"-c",
|
||||
"-n",
|
||||
"-p",
|
||||
"-P",
|
||||
"-u",
|
||||
"--class",
|
||||
"--classdata"
|
||||
],
|
||||
"xargs": [
|
||||
"-a",
|
||||
"-d",
|
||||
"-E",
|
||||
"-e",
|
||||
"-I",
|
||||
"-i",
|
||||
"-L",
|
||||
"-l",
|
||||
"-n",
|
||||
"-P",
|
||||
"-s",
|
||||
"--arg-file",
|
||||
"--delimiter",
|
||||
"--eof",
|
||||
"--replace",
|
||||
"--max-lines",
|
||||
"--max-args",
|
||||
"--max-procs",
|
||||
"--max-chars"
|
||||
],
|
||||
"exec": [
|
||||
"-a"
|
||||
],
|
||||
"nohup": [],
|
||||
"setsid": [],
|
||||
"command": [],
|
||||
"builtin": [],
|
||||
"time": [
|
||||
"-f",
|
||||
"-o",
|
||||
"--format",
|
||||
"--output"
|
||||
],
|
||||
"chronic": [],
|
||||
"unbuffer": [],
|
||||
"busybox": []
|
||||
},
|
||||
"keywords": [
|
||||
"{",
|
||||
"}",
|
||||
"(",
|
||||
")",
|
||||
"!",
|
||||
"if",
|
||||
"then",
|
||||
"else",
|
||||
"elif",
|
||||
"do",
|
||||
"while",
|
||||
"until",
|
||||
"time"
|
||||
],
|
||||
"shells": [
|
||||
"sh",
|
||||
"bash",
|
||||
"zsh",
|
||||
"dash",
|
||||
"ksh",
|
||||
"mksh",
|
||||
"fish",
|
||||
"ash"
|
||||
],
|
||||
"git_value_options": [
|
||||
"-C",
|
||||
"-c",
|
||||
"--git-dir",
|
||||
"--work-tree",
|
||||
"--namespace",
|
||||
"--exec-path",
|
||||
"--config-env"
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
{
|
||||
"about": "The four permission modes, as what each does with a call of each risk class once the hardline and the rules have spoken. `rules` means the permission rules decide (defaults.json, then the user's, then a trusted project's, then this session's approvals); anything the rules do not allow is asked. A deny from the rules or the hardline is final in every mode.",
|
||||
"order": ["auto", "edit", "manual", "plan"],
|
||||
"order_about": "Loosest first. A project or a subagent may make the mode stricter, never looser; switching to a looser mode is always asked.",
|
||||
"aliases": { "unrestricted": "auto" },
|
||||
"floor": "The hardline (hardline.json) and the protected paths are refused in every mode, auto included.",
|
||||
"modes": {
|
||||
"manual": {
|
||||
"summary": "Everything not already allowed is asked.",
|
||||
"read": "rules",
|
||||
"write": "rules",
|
||||
"execute": "rules",
|
||||
"interact": "rules"
|
||||
},
|
||||
"edit": {
|
||||
"summary": "Reading and changing files inside the project runs without asking; commands, and anything outside the project, follow the rules.",
|
||||
"read": "allow inside the project, unless a rule written for that tool says ask (reading .env still asks); outside the project: rules",
|
||||
"write": "allow inside the project, except git's own files (.git/) and the agent's own configuration in the project (config, agents, commands, skills); outside: rules",
|
||||
"execute": "rules",
|
||||
"interact": "rules"
|
||||
},
|
||||
"auto": {
|
||||
"summary": "Nothing is asked. The hardline still refuses.",
|
||||
"read": "allow",
|
||||
"write": "allow",
|
||||
"execute": "allow",
|
||||
"interact": "allow"
|
||||
},
|
||||
"plan": {
|
||||
"summary": "Investigate and write a plan; change nothing else.",
|
||||
"read": "rules",
|
||||
"write": "allow only for files under the plans directory; anything else is refused",
|
||||
"execute": "only what the rules already allow; anything else is refused",
|
||||
"interact": "rules"
|
||||
}
|
||||
},
|
||||
"unattended": "With nobody to answer, whatever a mode would ask is refused instead, and the model is told so up front (prompts/modes/unattended.md)."
|
||||
}
|
||||
Reference in new issue
Block a user