kigi allowed loopback unconditionally and missed several non-public ranges, and the SSRF check ran only on the initial URL. Policy (ssrf.rs): - loopback is blocked unless `[toolset.web_fetch] allow_local` (or KIGI_WEB_FETCH_ALLOW_LOCAL) is on, AND the URL names it explicitly, so a public name resolving to loopback stays blocked (DNS rebinding) - add 0.0.0.0/8, 100.64/10, 192.0.0.0/24, TEST-NET-1/2/3, 198.18/15, 240/4, IPv6 site-local and documentation prefixes - inherit the IPv4 verdict through mapped, compatible, NAT64 and 6to4 wrappers; network-specific NAT64 prefixes remain uncovered (see doc) Plumbing (client.rs), where the exploitable half lived: - re-check every redirect hop, not just the first - compare hosts exactly; a `www` sibling has its own A records, so it is a cross-host redirect rather than an auto-followed hop - run the check before the fetch service, so a blocked URL is never posted to an endpoint that egresses elsewhere - exempt explicit local hosts from the https upgrade and from the single-label filter, and re-upgrade each followed hop Wiring: allow_local reaches WebFetchParams from both construction paths; documented in the config guide and the README env table.
Kigi User Guide
Learn how to install, configure, and extend Kigi, the terminal-based AI coding assistant from SpaceXAI.
Tier 1: Essential User Docs
Start here. These guides cover what you need on your first day.
| # | Document | Description |
|---|---|---|
| 1 | Getting Started | Installation, first launch, authentication, basic interaction, and key concepts |
| 2 | Authentication | Browser login, API keys, OIDC/SSO, external auth providers, and device-code flow |
| 3 | Keyboard Shortcuts | Reference for every key binding and mouse action in the TUI |
| 4 | Slash Commands | Every / command for sessions, models, memory, hooks, and plugins |
| 5 | Configuration | config.toml, pager.toml, environment variables, and file locations |
Tier 2: Core Feature Docs
Customize and extend Kigi.
| # | Document | Description |
|---|---|---|
| 6 | Theming and Appearance | Themes, the /theme command, pager.toml, and color-support detection |
| 7 | MCP Servers | External tool integrations through the Model Context Protocol |
| 8 | Skills | Reusable prompt packages in the SKILL.md format |
| 9 | Plugins | Bundle and share skills, commands, agents, hooks, and MCP servers |
| 10 | Hooks | Lifecycle scripts and HTTP callbacks for pre- and post-tool-use events |
| 11 | Custom Models | Bring-your-own-key, Ollama, and OpenAI-compatible endpoints |
| 12 | Project Rules (AGENTS.md) | Per-directory AGENTS.md instructions and their precedence |
| 13 | Memory | Cross-session knowledge persistence with /flush, /dream, and hybrid search |
Tier 3: Advanced Usage Docs
Automate, script, and integrate Kigi with other systems.
| # | Document | Description |
|---|---|---|
| 14 | Headless Mode and Scripting | kigi -p, output formats, CI/CD integration, and piping |
| 15 | Agent Mode and IDE Integration | ACP stdio transport, WebSocket relay, and SDK integration |
| 16 | Subagents and Personas | Parallel child sessions, agent types, personas, and capability modes |
| 17 | Session Management | Save, load, resume, rewind, compact, and the session persistence format |
| 18 | Sandbox Mode | OS-level filesystem and network isolation profiles |
| 19 | Plan Mode | Structured planning, plan-file edits, and approval before coding |
| 20 | Background Tasks and Monitoring | background: true, /loop, monitor, and Ctrl+G to demote |
| 21 | Terminal Support and Troubleshooting | tmux, SSH, truecolor, clipboard, and OSC 52 |
| 22 | Permissions and Safety Controls | dontAsk mode, auto-approved tools, the safe-bash list, and restrictive PreToolUse hooks (such as git/gh-only) |