---
title: "Safer actions from deployed sites, stricter caches"
url: "https://miraweb.in/changelog/v0-2-1/"
description: "Actions from a deployed site cannot reach your own network, CMS caches are kept per token, and the agent audit catches pages agents cannot read."
date: "2026-10-08"
---

# Safer actions from deployed sites, stricter caches

### Security

- Actions read from a deployed site with `mira mcp --url` cannot reach `localhost` or loopback, private, or link-local addresses. The check runs on the address Mira actually connects to, so a public name that resolves to your own network is refused too.
- Actions from a deployed site always ask the person first, even when the site sets `confirm: false`. A confirmation covers the endpoint the person saw as well as the input.
- Responses from CMS and API sources are cached separately for each set of credentials. A source that refuses its token (HTTP 401 or 403) fails the build and drops its cached copy, so revoking a token stops its content from being published.

### Agent audit

- `mira audit --agent` refuses to run when `agents.twins` is `false`, since agents could not read any page, and flags pages without a Markdown copy instead of counting them as empty.
- A search index that is not valid JSON fails with its path and line.
- With `--json`, the report carries `passed`, which is `false` when any page is over budget or has no Markdown copy.

### Content

- A `<mira-frame>` tag split across lines in Markdown fails the build at that line. Markdown would have shown it as text.

### Links

- The README, the agent skills, and the npm and Cargo packages link to the Mira site at [miraweb.in](https://miraweb.in).
