ARexx port designed so the port never carries the passphrase (unlock is exclusively interactive). Command set: GETCODE, TIMELEFT, LIST (names only), STATUS, LOCK, UNLOCK (interactive prompt), SHOW/HIDE/QUIT. Optional per-vault "allow ARexx GETCODE" setting (default on). The security note must state plainly that any running program can drive the port while unlocked. From docs/ROADMAP.md v2 candidates + docs/SECURITY.md.
ARexx port designed so the port never carries the passphrase (unlock is exclusively interactive). Command set:
GETCODE,TIMELEFT,LIST(names only),STATUS,LOCK,UNLOCK(interactive prompt),SHOW/HIDE/QUIT. Optional per-vault "allow ARexx GETCODE" setting (default on). The security note must state plainly that any running program can drive the port while unlocked. From docs/ROADMAP.md v2 candidates + docs/SECURITY.md.