qmax-code is a local terminal agent. When you run it, it can act with the
same filesystem and process permissions as your user account.
The following tools are intentionally powerful:
read_filereads local files requested by the agent.edit_filemakes exact replacements in files inside the current workspace.write_filewrites files inside the current working directory.run_commandruns allowlisted local commands through the shell.run_local_testdownloads test code from QualityMax, executes supported test frameworks locally, and reports the result back to QualityMax.
These features are designed for trusted development workspaces. They are not a remote sandbox, container boundary, or permission system.
Start with qmax-code --local, or persist local_only=true, to run without a
QualityMax account. In this mode qmax-code does not load QualityMax credentials,
discover the legacy qmax CLI, start QualityMax cloud sessions, or expose
QualityMax-backed tools.
The built-in agent receives update_plan, read_file, run_command,
edit_file, and write_file. The MCP catalog omits update_plan because CLI
agents already provide native planning, leaving the four workspace tools.
Direct calls to undisclosed QualityMax tool names are rejected at execution
time as well as hidden during discovery.
run_local_test is intentionally excluded: it downloads test code from
QualityMax and reports results back. "Local-only" describes the QualityMax
service boundary, not all network traffic. Anthropic, Cerebras, Claude Code,
Codex, or OpenCode may still send prompts and repository context to their model
provider. A loopback Ollama endpoint is the self-hosted inference option.
CLI-agent native tools also remain governed by that agent's own permissions.
/orch, /cc, /codex, and /opencode can launch a coding-agent CLI with
qmax tools supplied through MCP.
- Standard mode auto-approves reads, searches, repository inspection, common test runners, and qmax tools. Other actions remain subject to the selected CLI's permission checks.
- Unattended mode grants the selected CLI full file and shell autonomy. The agent can edit files, run arbitrary commands, and perform git operations.
Only use Unattended mode in a trusted, recoverable workspace. Neither mode creates a sandbox or worktree boundary.
Claude Code, Codex, and Antigravity can optionally receive a user-level qmax MCP
entry in ~/.claude/settings.json, ~/.codex/config.toml, or
~/.gemini/config/mcp_config.json. That makes qmax tools available whenever
the CLI is launched, not only inside qmax-code. OpenCode uses a separate
qmax-managed overlay at ~/.qmax-code/opencode.json. Antigravity authenticates
with Google OAuth via interactive agy (browser sign-in); qmax-code does not store a Gemini API
key for that backend.
qmax-code also installs managed QA skills into the selected CLI's user-level skills directory. See Orchestration mode for the complete list of affected paths and scope choices.
- QualityMax credentials are stored in
~/.qmax-code/auth.jsonwith0600permissions. Use/disconnectto remove saved QualityMax auth. - Anthropic keys saved by the interactive prompt are stored in the OS keychain
under the
qmax-codeservice. You can also useANTHROPIC_API_KEYfor session-only auth. - Cerebras and opt-in OpenCode provider keys saved by qmax-code are stored in the OS keychain. Environment-variable overrides remain available for session-only or CI use.
- Disabling an OpenCode provider removes it from the model picker but retains its key for later reuse.
- Telemetry/error reporting is disabled by default. It only initializes when
both
QMAX_CODE_TELEMETRY=1andQMAX_CODE_TELEMETRY_DSNare set. - Common credential patterns are redacted before API errors, command output, local test output, or optional telemetry are displayed or reported.
run_command uses an executable allowlist and blocks shell control tokens such
as pipes, command substitution, redirection, and command chaining. This reduces
accidental damage, but it should not be treated as a security sandbox.
If you need to create or edit files, prefer the write_file tool path rather
than shell redirection.
Each qmax-code process that performs outbound LLM or cloud-API requests writes a signed local manifest under:
~/.qmax-code/receipts
Inspect and verify receipts with:
qmax-code receipt list
qmax-code receipt show latest
qmax-code receipt verify latestReceipts record structural egress metadata and do not include prompt bodies, file contents, LLM responses, shell output, or credential values. Offline signature verification proves local provenance; it does not independently prove completeness. Cross-check against network or proxy logs when complete egress accounting is required.
When qmax-code updates a QualityMax automation script, it stores a local backup under:
~/.qmax-code/script-backups
Review and remove old backups if they contain sensitive test code.
Please do not file public GitHub issues for security vulnerabilities.
Report vulnerabilities by emailing strazhnyk@gmail.com. Include a description of the issue, steps to reproduce, and any relevant environment details. You will receive a response within 48 hours. We ask that you give us reasonable time to address the issue before any public disclosure.
Saved conversations include user/assistant messages, tool inputs and outputs exposed to qmax-code, and native CLI session identifiers and workspace paths. They do not collect hidden reasoning, provider configuration, or credentials from the environment. Switching providers makes retained conversation content available to the newly selected provider.
Session writes use an owner-only temporary file and atomic replacement.
Portable transcripts in ~/.qmax-code/sessions/ are reclaimed after 90 days;
legacy sessions keep the seven-day cleanup. Large handoffs and built-in
compaction use an owner-only temporary directory containing a searchable
transcript. These temporary files are removed on clear, on normal exit, and on
the Ctrl+C / SIGTERM exit paths; only an uncatchable kill (SIGKILL,
power loss) can leave them in the OS temporary directory.
Structured credential fields are redacted before saving or transferring
archived content, along with unambiguous credential shapes in prose. Retained
content is redacted more conservatively than displayed content: it is replayed
as the conversation itself, so an over-eager match would silently corrupt the
only copy of your context. Redaction is best effort, not a substitute for
keeping secrets out of prompts and tool output. Turning off
auto-save prevents automatic qmax session writes, including on exit; /save
still writes explicitly. Native CLIs manage their own persistence independently.