Security
- Actions read from a deployed site with
mira mcp --urlcannot reachlocalhostor loopback, private, or link-local addresses. The check runs on the address Mira actually connects to, so a public name that resolves to your own network is refused too. - Actions from a deployed site always ask the person first, even when the site sets
confirm: false. A confirmation covers the endpoint the person saw as well as the input. - Responses from CMS and API sources are cached separately for each set of credentials. A source that refuses its token (HTTP 401 or 403) fails the build and drops its cached copy, so revoking a token stops its content from being published.
Agent audit
mira audit --agentrefuses to run whenagents.twinsisfalse, since agents could not read any page, and flags pages without a Markdown copy instead of counting them as empty.- A search index that is not valid JSON fails with its path and line.
- With
--json, the report carriespassed, which isfalsewhen any page is over budget or has no Markdown copy.
Content
- A
<mira-frame>tag split across lines in Markdown fails the build at that line. Markdown would have shown it as text.
Links
- The README, the agent skills, and the npm and Cargo packages link to the Mira site at miraweb.in.