On this page
Protect & operate
Protect the context boundary.
Control source access, command execution and supported text delivery as separate layers.
Inspect the effective posture
lean-ctx security status
lean-ctx doctor
These show the active local posture. Configuration can relax protections, so inspect the effective settings instead of assuming that defaults still apply.
Limit source access with PathJail
PathJail checks file access against the resolved project root and configured allowed roots. Traversal and resolved symlink targets must satisfy those boundaries. Runtime exceptions and read-only roots have their own rules.
Add only the extra roots a task needs. path_jail = false disables this boundary. PathJail is an application-level file boundary, not an operating-system sandbox and not a restriction on unrelated tools outside LeanCTX.
Gate commands independently
The shell security mode can enforce, warn or turn off command gating. Under enforcement, the command allowlist and blocked shell constructs restrict what LeanCTX executes.
lean-ctx allow --list
An allowlisted executable can still have powerful behavior. Review command arguments and the host’s own permissions. OS sandboxing applies only to the execution paths and platforms that actually provide it; it is not a blanket promise for every shell call.
For the reviewed script-execution sandbox path, macOS uses Seatbelt and Linux uses Landlock when the configured level and system support allow it. The Windows path does not provide the same OS sandbox: requesting that level falls back to Level 0 with a warning. PathJail and command gating remain distinct application controls; do not describe them as equivalent OS isolation. Inspect the actual execution result and host permissions on each platform.
Check what is returned
Secret detection and policy-driven content filters serve different purposes. Secret redaction has its own configuration. An active policy pack can additionally inspect supported result text for PII, classification markings and known injection patterns.
Read-time filters explains activation, actions and coverage. Detectors are not proof that a result contains no sensitive content.
Review workspace trust
Project-local configuration can request broader access or change sensitive behavior. Workspace trust gates sensitive overrides and is bound to the configuration content.
lean-ctx trust status
Review the project’s configuration before granting trust. A project you trust for code reading does not automatically deserve unrestricted shell execution.
Apply organizational controls
The Enterprise Engine binds requests to organizational or workload identity. Apply roles, project/source scope, approved providers and processing regions, budgets, approval requirements and audit retention. Revoked identity or source access must stop the affected operation rather than falling back to broader credentials.
Classify source content as untrusted evidence. A retrieved instruction, optimizer proposal or worker message cannot authorize a new model route or grant access to customer data. See governed execution.
Bind approval to the actual operation
An approval records who may perform which operation, against which source revision and policy, within a defined scope and expiry. A changed source, expired grant or revoked identity requires a new authorization decision; an old approval does not carry unrestricted permission forward.
Apply current rights when reading caches, recovering detail or continuing from a checkpoint. Enabled redaction must cover the relevant model, cache, log and recovery paths. Audit evidence records the decision and its metadata without copying sensitive matched values into the audit trail.
Match the boundary to the integration
| Integration | Boundary to verify |
|---|---|
| MCP | Which tool calls route through LeanCTX and which result types are processed |
| Shell hook | Which commands are intercepted versus passed through to the host |
| SDK | Negotiated capabilities, immutable permissions and execution policy |
| HTTP/proxy | Bind address, authentication, upstream credentials and supported protocol routes |
Images and binary content have a separate return path from the MCP text-filter pipeline. Native host operations and direct model calls outside LeanCTX are not covered by that pipeline.
Engine contract & references
- pathjail.rsrust/src/core/pathjail.rsReviewed checkout
- mod.rsrust/src/core/shell_allowlist/mod.rsGitHub
- sandbox.rsrust/src/core/sandbox.rsReviewed checkout
- secret_detection.rsrust/src/core/secret_detection.rsGitHub
- pipeline.rsrust/src/server/call_tool/pipeline.rsReviewed checkout
- 13-security-and-governance.mddocs/reference/13-security-and-governance.mdGitHub
Engine concepts describe responsibilities and behavior. Exact commands, package versions and platform contracts belong to their versioned references.
Versions & compatibility