Security & Trust Mechanism
To prevent accidental secret exposure or arbitrary code execution through malicious configuration files, Anzen implements a strict trust model inspired by tools like direnv.
The Trust Flow
- When you run any command in a project directory, Anzen checks if the
.anzen.tomlfile is trusted. - If the file hash is untrusted or unrecognized, Anzen refuses to read secrets or execute commands.
- You must explicitly review and trust the configuration. To do that, you can either
inspect the file yourself, or use
anzen summaryand then trust it:anzen trust - Anzen records the approved hash in global state, allowing safe execution until the configuration file is modified.