Safety¶
matchblox runs commands on your machine for you. These rules hold for every command.
- It reads, and does nothing to your agents, processes or checkouts by
itself. Every action starts from a key. The one exception is yours:
[hooks] alertin the config runs the command you name on each alert. - Every action shows its exact command before it runs.
Enternever runs a destructive action. That needsx, then a typedy.- Each step checks its facts again just before it runs: the same process and start time, a worktree still clean and unused, a session still idle. If a fact changed, the step does not run.
- Two consoles that confirm the same action run it once.
- Each step is a list of arguments, never a shell string built from data.
- matchblox runs as you, at the lowest CPU priority. It opens no network port. The service socket is in a directory that only you can open.
- It sends no pane text to a model.
- A setup step that edits a file (
~/.claude/settings.json,~/.tmux.conf) shows the exact change first and keeps a backup. - A remote host's stream uses its own key. That key can start only the stream, with a strict host key check and nothing forwarded.
To report a security problem, see SECURITY.md.