Skip to content

Security: daftpunkwav/wave-code

Security

SECURITY.md

Security Policy

Supported versions

Only the latest published release (and main) receives security fixes. wavecode is a local CLI tool; there is no server component and no backport cadence to older tags.

Reporting a vulnerability

Use GitHub's private security advisories for daftpunkwav/wave-code. Please do not open a public issue for anything exploit-looking.

Include: the affected command surface (exec / serve / acp / REPL), a reproduction (repo layout, config, invocation), and your assessment of impact. You will get an acknowledgement within a few days and a fix timeline once the report is triaged.

Scope

In scope:

  • Sandbox escapes: reads/writes/exec outside the workspace that the permission modes promise to confine, including Windows path semantics (backslashes, drive prefixes, junctions) and symlinks.
  • Approval bypasses: paths where a tool runs without the prompted consent, or a deny/allow decision is misapplied.
  • Credential handling: API keys or tokens leaking into session journals, exports, logs, error messages, or telemetry (there is no telemetry).
  • Network surfaces: the local app server (auth, origin checks), MCP client/server transport, and SSRF in web fetch/search.
  • Terminal integrity: untrusted text reaching the terminal as control sequences (escape injection, OSC abuse).
  • Supply chain: the install/update path (asset verification, self-update swap).

Out of scope:

  • Prompt injection making the model produce bad code within its granted permissions (an inherent LLM property; the sandbox is the boundary).
  • Attacks requiring local malware already running as the user.
  • Volumes/rate issues against external services.

Hardening notes

  • The path sandbox is deny-first with rules persisted per grant; wavecode doctor reports the effective confinement.
  • Release archives and the self-update path verify sha256 checksums before install; a failed verification aborts without touching the running binary. The checksum ships with the same release (no out-of-band signature chain) — the HTTPS github.com origin allowlist plus the checksum are the accepted trust root for self-update.
  • Untrusted text is sanitized through one shared terminal gate before rendering; notifications ride tmux-safe wrappers.
  • Provider credentials resolve from the env_key environment variable first; an inline api_key in config.toml is an accepted plaintext convenience — doctor reports the key source and flags inline storage, and the shell/script tools strip credential-shaped names from child-process environments.
  • Private files (journals, grants, spill store) are written mode 0600 on Unix; on Windows no extra ACL is applied because files under the user profile inherit owner-scoped default ACLs (accepted).
  • wavecode mcp serve exposes the full local tool registry to its stdio client with no approval gate: the local MCP client is the operator-configured, same-user process that spawned the server and is trusted (MCP places tool-approval responsibility on the client). Provider env_key names are still stripped from tool child environments on this surface; the session wave denylist is not consulted there (it is session-policy, not a serve-surface control).

There aren't any published security advisories