Security Model
Design principle
bake is a CLI that deploys real programs to real blockchains. The security model is designed around one principle: an agent cannot be tricked into calling a tool it does not know exists.
MCP safety model
Read-only by default
bake mcp starts in READ-ONLY mode. Write tools are not registered at all โ not "registered but blocked."
Policy-gated writes
To enable writes, create a policy file:
{
"allowWrites": true,
"maxDeploysPerSession": 5,
"requireConfirmation": true
}Confirmation flow
When requireConfirmation: true:
- Agent calls
bake_deploy - Server returns preview +
confirmationToken - Agent (or human) calls
bake_confirm_actionwith token - Server executes
A real deploy cannot complete in a single unsupervised tool call.
Session limits
maxDeploysPerSession caps writes per MCP server process. Counter resets on restart.
Audit logging
Every write attempt is logged to stderr with ISO timestamp.
Audit gating
bake deploy --require-audit
Runs Radar (Auditware's static analyzer) before deploying. Refuses to ship critical/high findings.
There is deliberately no --ignore-audit override.
Radar
bake implements no security heuristics of its own. All findings are Radar's, labelled "powered by Radar."
See Audit with Radar for details.
What bake never does
- โ Never signs transactions that aren't deploy-related
- โ Never exports private keys
- โ Never shares sessions with the dashboard
- โ Never auto-installs security scanners silently