Files
HomerandClaude Opus 5.5 f9bad01ed7
ci / check (push) Waiting to run
LLeMbas CLI 1.0.0
The first public release of LLeMbas CLI: a terminal coding agent and project manager for any LLM
API, with permission modes, git snapshots, memory and skills, knowledge bases, MCP, voice, and a
link to a LLeMbas instance whose web UI can work its sessions too. Signed Linux binaries for x64
and arm64.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-09 21:59:03 +00:00

2.7 KiB

Security

Reporting a problem

Please report a vulnerability privately, not in a public issue: on GitHub, Security → Report a vulnerability on LLeMbas/LLeMbas-CLI.

Say what it is, how to reproduce it, and which version (lembas --version). You will get an answer within a week. Fixes go out as a release, and the CHANGELOG says what was fixed once the release is out.

Supported versions

Only the newest release. LLeMbas CLI updates itself (update.auto), so staying on it is the default.

What counts

LLeMbas CLI runs commands and changes files for a language model, so the model's output — and everything the model reads: files, web pages, tool results, MCP servers — is treated as untrusted. A report is most useful when it shows one of these:

  • a tool call that runs, or changes something, without the approval the permission mode and rules say it needs — including a way past the hardline list (refused in every mode) or a write to a protected path (~/.ssh, ~/.gnupg, connections.yaml);
  • something a repository can do before the user trusts it, or in read-only mode, beyond being read; or anything that weakens a global-only setting from a project;
  • a way for the agent to change a setting it must not (permission rules, the hardline, MCP servers, connections, the update source or key, settings_tool), or to loosen the permission mode without being asked every time;
  • an update that installs without a valid signature from the release key, an older release installed as an update, or files written outside where the installer and uninstaller say;
  • secrets — API keys, OAuth tokens — written somewhere readable, logged, or sent to a host other than the one they belong to.

A model doing something unwise with the user's approval, or in unrestricted mode, is how LLeMbas CLI is meant to work, not a vulnerability; ways to make that clearer are still welcome as ordinary issues (GitHub Issues).

Verifying a release

Each release's SHA256SUMS is signed with the release key, an SSH ed25519 key used for nothing else:

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDSZO3Byow7R3ZpOH3MCvpPIga2pZBzhfX5wXfNP1cLa
SHA256:aPrR1ptc5sIwmyJgmqtu1iXmciq466Wv9kZNfm8Ddmg

get.sh and the updater check it before installing anything. By hand:

echo "lembas-release ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDSZO3Byow7R3ZpOH3MCvpPIga2pZBzhfX5wXfNP1cLa" > allowed
ssh-keygen -Y verify -f allowed -I lembas-release -n lembas-release -s SHA256SUMS.sig < SHA256SUMS
sha256sum -c --ignore-missing SHA256SUMS

Tags and commits are signed too (SSH signatures, shown as verified on the forge).