The note can now change the machine.
Ledge 0.1.5 is an Apache 2.0 Markdown notebook with downloadable releases for macOS, Linux, and Windows. Its docs say a closed fenced block can run in place. Output stays under the block. Shell blocks in one note share a persistent shell, so a directory change or exported variable carries into the next run.[1]
That design closes a common gap. The command, explanation, and result can occupy one readable file. It also changes the job of the note. A block is no longer only an example. It may inherit state and act on the current machine.
The useful question is not "Can this note run?" Ask what this block may change, where it runs, and what remains after it stops.
Put the brake in the file.
Ledge adds two plain markers to a fence. confirm opens a dialog that shows the code and execution location. Cancel has initial focus. norun removes the Run control while leaving the block available to read and copy. The docs call confirmation a speed bump, not a lock, because anyone who can edit the note can remove it.[2]
That distinction is sound. A visible prompt can interrupt muscle memory. It cannot replace operating-system permissions, repository policy, or a restricted credential. Use the marker to declare intent. Use the execution environment to enforce authority.
Place belongs beside the command.
A runnable note may act in a persistent local shell, on the server that stores the note, or on another host named in frontmatter. Ledge says remote runs use the operator's SSH configuration. It also says named profiles keep environment variables outside the notes folder.[3]
Do not make the reader infer place from prose written three screens earlier. Put the working directory and host beside the block. If the same command can target several hosts, require a fresh choice. A copied note should fail closed when its named place is missing.
Agent access needs a separate label.
Ledge ships an MCP server with read and write tools for notes. Its agent documentation lists eleven tools. It says the agent route has no delete tool, locked-note bodies are withheld, and settings can be read but not changed through that route.[4]
Those limits describe note access. They do not prove that a command inside an editable note is safe to run. Keep content authority and shell authority separate. Record which route edited the block, then apply execution checks at run time.