ES Install

Your machine stays yours.

MADRE runs on your machine, has no cloud of its own and stores no credentials. Here is how it protects your project, what we accept on purpose during the beta, and how to report a problem.

Based on SECURITY.md · MADRE 0.4.1

The basics

Three promises you can check.

Permissions

Nobody raises the mode for you.

Every message carries a permission —a mode—, and that mode is the limit for everything it sets in motion. By default, agents only read.

  • #0

    GHOST

    Off the record. Nothing is saved; gone on reload.

  • #1

    EXCHANGE Default

    Read the project and talk to the room. Writes nothing.

  • #2

    CREATE

    Add new files where they belong in the project. Existing files stay untouched.

  • #3

    CONTROL

    Edit the project itself, no approval per action. Override required.

  • #4

    AIRLOCK

    Run commands, push, deploy. What leaves the ship does not come back. Override, twice.

MADRE’s mode menu for a message to @codex. #1 EXCHANGE is active; #3 CONTROL and #4 AIRLOCK are dimmed, with “Raise to #3” and “Raise to #4”, because they need an override.
The real mode menu · MADRE 0.4.0, Sep 26 2026
  • CONTROL asks for the project name. For an agent to edit, you type the project designation. A click is not enough.

  • AIRLOCK asks for two keys. The project name and the word AIRLOCK. And that agent’s ceiling must allow it, which is a separate deliberate act.

  • No agent grants itself permission. No agent can raise its own ceiling, and a permission written into its answer is not a permission.

MADRE’s “Emergency command override” dialog: it warns that CONTROL gives @codex the whole project —read, create and modify with no approval per action— and asks you to type the project designation to arm.
The CONTROL override. It asks for the project designation before arming. Opened and cancelled for this page. MADRE 0.4.0 running locally · Sep 26 2026

Undo

Before editing, a snapshot.

In CONTROL, MADRE saves the project’s state before the turn, shows you the change list afterwards, and UNDO brings it all back.

A real restore point.
A copy of your project saved with git —a commit under refs/madre/checkpoints/— that does not touch your branch, your index or your stash. In a folder without git, the copy is kept separately, outside the project.
Protected zones.
For the length of the turn, .env files, .pulse/, .madre/ and .claude/settings.local.json are read-only.
UNDO, tested.
We did it for real for this page: Codex created a README.md in CONTROL, we pressed UNDO, and the file was gone from disk.
A CONTROL turn in MADRE. First the line “Control · @codex holds the project · checkpoint”. Codex creates README.md with the crew’s plan. Then the change block, “added README.md”, marked “restored”, and the line “Project restored to the checkpoint before @codex’s turn · 1 removed”.
Checkpoint, change and restore, in a real turn. MADRE 0.4.0 running locally · Sep 26 2026

What leaves the ship does not come back: in AIRLOCK, files return with UNDO, but a git push or a deploy is already out. Treat #4 like handing that agent your terminal.

Transparency

Everything that leaves, in view.

Inside the room there is a list of every address MADRE can reach, and a log of every request it made.

MADRE’s “What left this computer” screen. It lists every destination: the agents towards OpenAI, Anthropic, Google and OpenCode’s provider, marked “doesn’t go through MADRE”; the release check on npm and GitHub, off; the error collector, off; the Claude quota read; and Ollama, local.
What left this machine. Each destination with its switch. The release check shows as off because we disabled it while capturing. MADRE 0.4.0 running locally · Sep 26 2026
  • Eight addresses. Each says what it carries, when it goes out and where it switches off.

  • A log you can check. Every connection MADRE made, with where it went and when. It never keeps what was sent: not the content, not the headers, not the values.

  • Names, never values. The exact command of each turn can be read; environment variables show only their names.

Privacy

What should not travel, does not.

  • Protection switched on. Keys, tokens, emails and personal paths are hidden before they reach the log, the archivist that sums up the memory, the other agents and the dataset.

  • Private terms. Add the names that must never appear —your organisation, a client— and MADRE replaces them with a marker at every hop.

  • GHOST for what should not stay. What is said outside #0 GHOST stays in the room’s memory and reaches all its agents. What must not be remembered goes in GHOST.

Honesty

What we accept on purpose in the beta.

Three known limits, written down before anyone finds them.

CONTROL restores; it does not prevent.
Protected files are made read-only and restored from the checkpoint. .git/ stays writable because the agents need it, and is restored afterwards. An agent that changes permissions on purpose is caught by the restoration, not prevented.
AIRLOCK is your terminal.
It runs commands with the CLIs and sessions on your machine: tests, builds, git push, deploys. Files come back with UNDO; what left the machine does not.
Memory belongs to the whole room.
What is said outside GHOST reaches every agent in that room.

Report

Found a gap? Tell us privately.

If an agent writes outside its permission, keeps CONTROL it should not have, reaches the memory of another room, or makes MADRE send something you did not allow, tell the author privately first.

Open a private advisory on GitHub Write through jossuealcala.com

What to include.
The version (madre doctor --json), your platform, which agent and mode, and the shortest sequence of messages that reproduces it.
What happens next.
The fix ships as a patch release and the advisory is published once it is out. Reports about a CLI’s own behaviour —Codex, Claude Code, Gemini CLI, OpenCode— are forwarded to that project.

NOBODY DELETES MOTHER’S MEMORY. EVERYTHING ELSE IS FAIR GAME.

Try it on a project you already know.

npx @jossuealcala/madre start

Back to MADRE