This is documentation plus type-only contracts. It contains no agent runtime, no prompts, no credentials, no configuration files and no private code. The traces are synthetic, and the benchmark aggregates contain no task content.
- Local-first. Inference runs on the developer's machine, and code doesn't leave it.
- Least privilege by mode. ASK, PLAN and REVIEW are read-only. Mutation and verification require human approval.
- No free-form shell. Only declared tools run, and verification is limited to discovered project scripts.
- Path safety. Workspace containment, symlink-escape rejection, and time-of-check/time-of-use protection on writes.
- Stale-base guard. A patch applies only if the file still matches the content it was written against.
- Write-ahead durability. No side effect happens without a prior durable record; if the record can't be written, execution stops.
- Approvals don't survive restarts, so an approval can't be replayed.
- Untrusted input. Repository content and MCP tool descriptions are treated as data. MCP schemas are size-bounded.
- Secrets. Secret-like values are kept out of model context and logs.
If you believe something here exposes sensitive information, please open a private security advisory on this repository instead of a public issue.