Please do not open a public issue for a security problem.
Use GitHub's private vulnerability reporting on this repository: Report a vulnerability.
You should get an acknowledgement within a few days. If a fix is needed, it ships in the next release and the advisory is published alongside it with credit, unless you ask otherwise.
archeus releases from main and only the latest version on PyPI is supported.
There are no maintenance branches.
archeus runs locally, on your own machine, against files Claude Code already writes. The parts worth reporting are:
-
The local HTTP server behind the desktop GUI (
claude_sessions/gui.py,gui_api.py). It binds loopback and is guarded by aHostallowlist, a rejection of browser fetch metadata, and a per-run token. A way past any of those is a real finding — including anything reachable through DNS rebinding. -
The failover proxy (
claude_sessions/failover.py), which substitutes your OmniRoute key into requests it forwards. -
Credential handling. archeus reads Claude Code's own state and never writes
.credentials.json. Anything that leaks a token, an API key or a session id into a log, an error message, a generated file or an outbound request is in scope.Two exposures are deliberate, so that they are not reported as surprises. The per-run GUI token rides in the address bar (
/?k=…), because a top-level navigation cannot carry a header and stripping it would break reload; it is per-process and inert once archeus exits. And the Claude Code settings editor shows that account'senvblock, which is where anANTHROPIC_API_KEYwould live — it is an editor for your own file, behind the same token as everything else. A way to read either without the token is in scope. -
Path handling. Project paths, config directories and transcript names come from disk and from Claude Code. A traversal out of an account's config directory is in scope.
-
Anything archeus writes to a file another program parses —
settings.jsonabove all, which belongs to Claude Code, not to us.
- Claude Code itself, or the Claude API. Report those to Anthropic.
- Third-party agents and skills installed through archeus's library — those are the upstream projects' code and archeus shows you the source before writing it.
- Anything that requires an attacker who already has local user-level access to your machine. At that point they can read the same files archeus reads.
- Models generating wrong or unsafe suggestions. archeus shows you every generated hook, agent and CLAUDE.md block before it writes one, and that review is what you are relying on.