Mira
Changelog

0.2.1

Safer actions from deployed sites, stricter caches

Actions from a deployed site cannot reach your own network, CMS caches are kept per token, and the agent audit catches pages agents cannot read.

Security

  • Actions read from a deployed site with mira mcp --url cannot reach localhost or loopback, private, or link-local addresses. The check runs on the address Mira actually connects to, so a public name that resolves to your own network is refused too.
  • Actions from a deployed site always ask the person first, even when the site sets confirm: false. A confirmation covers the endpoint the person saw as well as the input.
  • Responses from CMS and API sources are cached separately for each set of credentials. A source that refuses its token (HTTP 401 or 403) fails the build and drops its cached copy, so revoking a token stops its content from being published.

Agent audit

  • mira audit --agent refuses to run when agents.twins is false, since agents could not read any page, and flags pages without a Markdown copy instead of counting them as empty.
  • A search index that is not valid JSON fails with its path and line.
  • With --json, the report carries passed, which is false when any page is over budget or has no Markdown copy.

Content

  • A <mira-frame> tag split across lines in Markdown fails the build at that line. Markdown would have shown it as text.
  • The README, the agent skills, and the npm and Cargo packages link to the Mira site at miraweb.in.