Files
routstrd/SECURITY.md
T
hzrd149andClaude Opus 5 5b4ddf79c4 chore(docs): remove shipped planning docs, refresh CLI reference
Audit of the repo's non-source documentation and ad-hoc scripts.

Deleted (work already shipped, or scratch files):
- IMPLEMENTATION.md — the ~/.cocod → ~/.routstrd/wallet migration plan;
  shipped as src/daemon/wallet/{migration,paths}.ts.
- src/TUI refactor.md — plan to move src/cli/usage-tui.ts into src/tui/;
  done, src/cli/ no longer exists.
- v1-messages-format-report.md — the Messages-API passthrough bug it
  describes is fixed; http/index.ts now forwards path: url.pathname.
- routstr-cost-logging.md — note about the routstr proxy's cost fields vs
  pi-ai; not about this codebase.
- refund.js, refund_new.js — one-off scripts with hardcoded Cashu tokens.
- test_box.ts, test_split_box.ts, test_split_box2.ts — manual renderBox
  eyeball checks that asserted nothing and bun test never ran.

Moved:
- COCO-2.0.0-MIGRATION-PLAN.md → docs/plans/coco-2.0.0-migration.md, with a
  status header. This one is genuinely unexecuted: package.json is still on
  coco-core 1.0.1 / coco-cashu-core 1.1.2-rc.50, and its NPC compatibility
  gate is unresolved.

Added:
- src/tui/usage/render.test.ts — real assertions for what the three deleted
  scratch scripts checked by eye (box width with and without a title, ANSI
  padding, side-by-side composition including unequal heights). renderBox
  had no coverage before.

Updated:
- SKILL.md — ships in the npm package as the CLI reference but was missing
  ~15 commands (wallet doctor/cleanup/npc, nwc and auto-refill, history,
  ping, providers reviews, service install/uninstall/logs, daemon, local,
  update, refund, top, send/receive shortcuts). Also dropped the claim that
  onboard installs cocod (the wallet is in-process), removed two orphaned
  tables misfiled under `routstrd refresh`, and completed the config and
  env-var tables.
- README.md — same cocod correction, points at SKILL.md for the full command
  reference, fixes the stale Project Structure tree and the POST / endpoint
  description.
- SECURITY.md — drop the stray `## SECURITY.md` line above the real heading.
- package.json — add a `smoke` script so scripts/smoke/chat-completions.sh
  stops looking orphaned. Deliberately not wired into CI: it needs a funded
  API key.

Note: the Cashu tokens in the deleted refund scripts remain in git history.
They date from March/April 2026 and were being POSTed to refund endpoints, so
they are almost certainly spent — flagging rather than rewriting history.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UW5RBn7pxSuHbDQjtHfQVW
2026-09-09 14:49:25 -05:00

22 lines
729 B
Markdown

# Security Policy
## Reporting a Vulnerability
Please report suspected security vulnerabilities privately to **team@routstr.com**.
Do not open a public GitHub issue or disclose the vulnerability publicly until we have had a
reasonable opportunity to investigate and coordinate a fix.
Please include, where possible:
- The affected Routstr package and version or commit
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
Do not include real Cashu tokens, seed phrases, private keys, or other secrets.
We will acknowledge your report and coordinate remediation and disclosure with you.
## Supported Versions
Security fixes are provided for the latest released version.