mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-26 15:40:18 +00:00
Implements hybrid-custody NEAR key management where the agent holds scoped function-call keys for routine operations while high-value operations require explicit user approval through the existing channel approval flow. Core infrastructure: - Ed25519 key generation/import via ed25519-dalek (not near-crypto) - AES-256-GCM encrypted storage via existing SecretsStore - Hand-rolled borsh-serializable NEAR transaction types - NEP-413 intent signing and MPC chain signature support - Configurable policy engine with transaction analysis pipeline - Daily spend tracking with automatic midnight UTC reset - Encrypted backup/restore with Argon2id KDF - CLI subcommands: generate, import, list, info, remove, export, policy, backup, restore - NEAR ed25519 secret key leak detection (Critical/Block) - WASM sign-payload host function (keys never enter WASM memory) - KeyManager wired into AgentDeps for agent-wide access Security invariants: private keys never reach the LLM or WASM boundary, signing happens in host Rust code with Zeroize on drop, every transaction is analyzed before signing, most-restrictive policy rule wins. Co-Authored-By: Claude Opus 4.6 <[email protected]>
105 lines
2.8 KiB
Rust
105 lines
2.8 KiB
Rust
//! CLI command handling.
|
|
//!
|
|
//! Provides subcommands for:
|
|
//! - Running the agent (`run`)
|
|
//! - Interactive onboarding wizard (`onboard`)
|
|
//! - Managing configuration (`config list`, `config get`, `config set`)
|
|
//! - Managing WASM tools (`tool install`, `tool list`, `tool remove`)
|
|
//! - Managing MCP servers (`mcp add`, `mcp auth`, `mcp list`, `mcp test`)
|
|
//! - Querying workspace memory (`memory search`, `memory read`, `memory write`)
|
|
//! - Checking system health (`status`)
|
|
|
|
mod config;
|
|
pub mod key;
|
|
mod mcp;
|
|
pub mod memory;
|
|
pub mod status;
|
|
mod tool;
|
|
|
|
pub use config::{ConfigCommand, run_config_command};
|
|
pub use key::{KeyCommand, run_key_command};
|
|
pub use mcp::{McpCommand, run_mcp_command};
|
|
pub use memory::{MemoryCommand, run_memory_command};
|
|
pub use status::run_status_command;
|
|
pub use tool::{ToolCommand, run_tool_command};
|
|
|
|
use clap::{Parser, Subcommand};
|
|
|
|
#[derive(Parser, Debug)]
|
|
#[command(name = "ironclaw")]
|
|
#[command(
|
|
about = "Secure personal AI assistant that protects your data and expands its capabilities"
|
|
)]
|
|
#[command(version)]
|
|
pub struct Cli {
|
|
#[command(subcommand)]
|
|
pub command: Option<Command>,
|
|
|
|
/// Run in interactive CLI mode only (disable other channels)
|
|
#[arg(long, global = true)]
|
|
pub cli_only: bool,
|
|
|
|
/// Skip database connection (for testing)
|
|
#[arg(long, global = true)]
|
|
pub no_db: bool,
|
|
|
|
/// Single message mode - send one message and exit
|
|
#[arg(short, long, global = true)]
|
|
pub message: Option<String>,
|
|
|
|
/// Configuration file path (optional, uses env vars by default)
|
|
#[arg(short, long, global = true)]
|
|
pub config: Option<std::path::PathBuf>,
|
|
|
|
/// Skip first-run onboarding check
|
|
#[arg(long, global = true)]
|
|
pub no_onboard: bool,
|
|
}
|
|
|
|
#[derive(Subcommand, Debug)]
|
|
pub enum Command {
|
|
/// Run the agent (default if no subcommand given)
|
|
Run,
|
|
|
|
/// Interactive onboarding wizard
|
|
Onboard {
|
|
/// Skip authentication (use existing session)
|
|
#[arg(long)]
|
|
skip_auth: bool,
|
|
|
|
/// Reconfigure channels only
|
|
#[arg(long)]
|
|
channels_only: bool,
|
|
},
|
|
|
|
/// Manage configuration settings
|
|
#[command(subcommand)]
|
|
Config(ConfigCommand),
|
|
|
|
/// Manage WASM tools
|
|
#[command(subcommand)]
|
|
Tool(ToolCommand),
|
|
|
|
/// Manage NEAR blockchain keys
|
|
#[command(subcommand)]
|
|
Key(KeyCommand),
|
|
|
|
/// Manage MCP servers (hosted tool providers)
|
|
#[command(subcommand)]
|
|
Mcp(McpCommand),
|
|
|
|
/// Query and manage workspace memory
|
|
#[command(subcommand)]
|
|
Memory(MemoryCommand),
|
|
|
|
/// Show system health and diagnostics
|
|
Status,
|
|
}
|
|
|
|
impl Cli {
|
|
/// Check if we should run the agent (default behavior or explicit `run` command).
|
|
pub fn should_run_agent(&self) -> bool {
|
|
matches!(self.command, None | Some(Command::Run))
|
|
}
|
|
}
|