Files
routstrd/SECURITY.md
T
hzrd149andClaude Opus 5 5b4ddf79c4 chore(docs): remove shipped planning docs, refresh CLI reference
Audit of the repo's non-source documentation and ad-hoc scripts.

Deleted (work already shipped, or scratch files):
- IMPLEMENTATION.md — the ~/.cocod → ~/.routstrd/wallet migration plan;
  shipped as src/daemon/wallet/{migration,paths}.ts.
- src/TUI refactor.md — plan to move src/cli/usage-tui.ts into src/tui/;
  done, src/cli/ no longer exists.
- v1-messages-format-report.md — the Messages-API passthrough bug it
  describes is fixed; http/index.ts now forwards path: url.pathname.
- routstr-cost-logging.md — note about the routstr proxy's cost fields vs
  pi-ai; not about this codebase.
- refund.js, refund_new.js — one-off scripts with hardcoded Cashu tokens.
- test_box.ts, test_split_box.ts, test_split_box2.ts — manual renderBox
  eyeball checks that asserted nothing and bun test never ran.

Moved:
- COCO-2.0.0-MIGRATION-PLAN.md → docs/plans/coco-2.0.0-migration.md, with a
  status header. This one is genuinely unexecuted: package.json is still on
  coco-core 1.0.1 / coco-cashu-core 1.1.2-rc.50, and its NPC compatibility
  gate is unresolved.

Added:
- src/tui/usage/render.test.ts — real assertions for what the three deleted
  scratch scripts checked by eye (box width with and without a title, ANSI
  padding, side-by-side composition including unequal heights). renderBox
  had no coverage before.

Updated:
- SKILL.md — ships in the npm package as the CLI reference but was missing
  ~15 commands (wallet doctor/cleanup/npc, nwc and auto-refill, history,
  ping, providers reviews, service install/uninstall/logs, daemon, local,
  update, refund, top, send/receive shortcuts). Also dropped the claim that
  onboard installs cocod (the wallet is in-process), removed two orphaned
  tables misfiled under `routstrd refresh`, and completed the config and
  env-var tables.
- README.md — same cocod correction, points at SKILL.md for the full command
  reference, fixes the stale Project Structure tree and the POST / endpoint
  description.
- SECURITY.md — drop the stray `## SECURITY.md` line above the real heading.
- package.json — add a `smoke` script so scripts/smoke/chat-completions.sh
  stops looking orphaned. Deliberately not wired into CI: it needs a funded
  API key.

Note: the Cashu tokens in the deleted refund scripts remain in git history.
They date from March/April 2026 and were being POSTed to refund endpoints, so
they are almost certainly spent — flagging rather than rewriting history.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UW5RBn7pxSuHbDQjtHfQVW
2026-09-09 14:49:25 -05:00

729 B

Security Policy

Reporting a Vulnerability

Please report suspected security vulnerabilities privately to team@routstr.com.

Do not open a public GitHub issue or disclose the vulnerability publicly until we have had a reasonable opportunity to investigate and coordinate a fix.

Please include, where possible:

  • The affected Routstr package and version or commit
  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof of concept

Do not include real Cashu tokens, seed phrases, private keys, or other secrets.

We will acknowledge your report and coordinate remediation and disclosure with you.

Supported Versions

Security fixes are provided for the latest released version.