Security

We designed the Sume CLI for agent use. But CLI output can still contain sensitive data or data that users own. Be careful with auth, job, and media output.

Secrets

Do not print or commit these items:

  • SUME_API_KEY,
  • local ~/.sume-com/config.json,
  • raw provider payloads.

For automation, use environment variables or secret managers:

For local development, the best choice is sume login. Then the CLI uses the CLI login approval flow to create and store a scoped key. Manual keys are in the API Keys dashboard.

Write and paid gates

You must add a confirmation flag to current write commands.

GateUse for
--confirm-submitNon-paid writes such as job cancellation.
--confirm-paidProvider-backed Avatar 1.0 and Avatar Video 1.0 runs that can reserve or spend credits. Image/Video/Music are API-first at this time. Apply the same confirmation discipline in your HTTP client.

Agents must confirm the intent of the user. When agents do a test, they must submit one bounded job first. Agents must recover the jobs that already exist and must not blindly retry paid commands.

Media URLs

Sume job results can include first-party media URLs. These URLs are public, but they are still user data.

When you report results:

  • summarize the media counts and the file types,
  • when possible, use local filenames, not full remote URLs,
  • redact query strings and private identifiers,
  • do not dump large raw result payloads.

Bug reports

When they help, include sanitized command names, error codes, request ids, and job ids. Do not include API keys, signed URLs, full private media URLs, raw provider payloads, emails, or workspace/user ids. The only exception is when engineering explicitly asks for them.