Skip to content
Documentation

Protect & operate

Protect the context boundary.

Control source access, command execution and supported text delivery as separate layers.

AvailableReviewed September 2026
Access boundaries and configured text filters apply to supported operations—not every host call.

Inspect the effective posture

lean-ctx security status
lean-ctx doctor

These show the active local posture. Configuration can relax protections, so inspect the effective settings instead of assuming that defaults still apply.

Limit source access with PathJail

PathJail checks file access against the resolved project root and configured allowed roots. Traversal and resolved symlink targets must satisfy those boundaries. Runtime exceptions and read-only roots have their own rules.

Add only the extra roots a task needs. path_jail = false disables this boundary. PathJail is an application-level file boundary, not an operating-system sandbox and not a restriction on unrelated tools outside LeanCTX.

Gate commands independently

The shell security mode can enforce, warn or turn off command gating. Under enforcement, the command allowlist and blocked shell constructs restrict what LeanCTX executes.

lean-ctx allow --list

An allowlisted executable can still have powerful behavior. Review command arguments and the host’s own permissions. OS sandboxing applies only to the execution paths and platforms that actually provide it; it is not a blanket promise for every shell call.

For the reviewed script-execution sandbox path, macOS uses Seatbelt and Linux uses Landlock when the configured level and system support allow it. The Windows path does not provide the same OS sandbox: requesting that level falls back to Level 0 with a warning. PathJail and command gating remain distinct application controls; do not describe them as equivalent OS isolation. Inspect the actual execution result and host permissions on each platform.

Check what is returned

Secret detection and policy-driven content filters serve different purposes. Secret redaction has its own configuration. An active policy pack can additionally inspect supported result text for PII, classification markings and known injection patterns.

Read-time filters explains activation, actions and coverage. Detectors are not proof that a result contains no sensitive content.

Review workspace trust

Project-local configuration can request broader access or change sensitive behavior. Workspace trust gates sensitive overrides and is bound to the configuration content.

lean-ctx trust status

Review the project’s configuration before granting trust. A project you trust for code reading does not automatically deserve unrestricted shell execution.

Apply organizational controls

The Enterprise Engine binds requests to organizational or workload identity. Apply roles, project/source scope, approved providers and processing regions, budgets, approval requirements and audit retention. Revoked identity or source access must stop the affected operation rather than falling back to broader credentials.

Classify source content as untrusted evidence. A retrieved instruction, optimizer proposal or worker message cannot authorize a new model route or grant access to customer data. See governed execution.

Bind approval to the actual operation

An approval records who may perform which operation, against which source revision and policy, within a defined scope and expiry. A changed source, expired grant or revoked identity requires a new authorization decision; an old approval does not carry unrestricted permission forward.

Apply current rights when reading caches, recovering detail or continuing from a checkpoint. Enabled redaction must cover the relevant model, cache, log and recovery paths. Audit evidence records the decision and its metadata without copying sensitive matched values into the audit trail.

Match the boundary to the integration

Integration Boundary to verify
MCP Which tool calls route through LeanCTX and which result types are processed
Shell hook Which commands are intercepted versus passed through to the host
SDK Negotiated capabilities, immutable permissions and execution policy
HTTP/proxy Bind address, authentication, upstream credentials and supported protocol routes

Images and binary content have a separate return path from the MCP text-filter pipeline. Native host operations and direct model calls outside LeanCTX are not covered by that pipeline.

Engine contract & references6 references Reviewed

Engine concepts describe responsibilities and behavior. Exact commands, package versions and platform contracts belong to their versioned references.

Versions & compatibility