StarForge uses layered confirmation prompts for operations that move real funds, reveal secrets, or deploy to mainnet. This document covers challenge phrases, automation bypass rules, and audit logging.
| Level | Typical operations | Prompt style |
|---|---|---|
| Low | Read-only previews, dry-runs | [y/N] |
| Medium | Testnet deploys, non-destructive writes | [y/N] |
| High / destructive | Mainnet deploy, secret reveal, account merge | Typed challenge phrase |
Destructive actions require typing an exact, case-sensitive phrase. Whitespace
at the start or end is trimmed; shortcuts like yes or pasted multiline text are
rejected.
| Action | Phrase | Commands |
|---|---|---|
| Mainnet deploy | deploy-mainnet |
starforge deploy --network mainnet --execute |
| Secret reveal | reveal-secret |
starforge wallet show <NAME> --reveal |
| Account merge | wallet name (override) | starforge wallet merge --from … |
| Mainnet transaction | send-mainnet |
starforge tx send --network mainnet |
| Mainnet contract invoke | invoke-mainnet |
starforge contract invoke --network mainnet |
Account merge uses the source wallet name as the challenge phrase so operators must deliberately name the account being closed.
For contract invocations (starforge contract invoke), the confirmation screen decodes the auth entries returned by the transaction simulation and renders them as a hierarchical invocation tree.
This ensures operators can see exactly which nested sub-invocations they are authorizing before signing, mitigating blind-signing attacks.
- Contract Aliases: Known contracts (defined in config) are displayed with their aliases. Unknown contracts are flagged.
- Transfers and Approvals: Critical token operations like
transferandapproveare visually highlighted. - Hardware Wallets: The same decoded invocation tree is displayed when signing via hardware wallet (Ledger/Trezor).
Non-interactive environments (CI, piped stdin, --non-interactive) fail fast
with a clear error instead of blocking on stdin.
| Scenario | Behavior |
|---|---|
Medium-risk + --yes |
Confirmation skipped (unchanged) |
Destructive + --yes only |
Blocked — requires unsafe opt-in |
Destructive + --yes + unsafe env |
Allowed with a logged warning |
To skip destructive confirmations in controlled automation, set both:
export STARFORGE_UNSAFE_SKIP_CONFIRMATION=1
starforge deploy --network mainnet --execute --yes …This bypass is:
- Explicit — the env var name signals danger
- Logged — every outcome is recorded via structured logging (no secrets)
- Documented — flagged here and in SECURITY_LOGGING_GUIDE.md
Do not set STARFORGE_UNSAFE_SKIP_CONFIRMATION in developer shells or shared
CI secrets unless the pipeline is scoped to non-production automation.
Confirmation results are logged at INFO with:
confirmation_action— e.g.mainnet_deploy,secret_revealconfirmation_networkconfirmation_outcome—Confirmed,Cancelled,SkippedDryRun,SkippedUnsafeBypassconfirmation_unsafe_bypass— whether the unsafe env var was set
User input (typed phrases, secrets) is never logged.
- COMMAND_REFERENCE.md — command flags
- SECURITY_LOGGING_GUIDE.md — logging standards
- DEPLOY_POLICY.md — organization deploy gates