SECURE AGENT EXECUTION

Give agents a guarded execution path, not an unrestricted machine.

The browser never reaches arbitrary directories on a user's computer. PiGO limits work to registered server-side Git directories and isolated worktrees, with separate controls for tools, paths, plugins, credentials, and release actions.

01

Register the workspace before execution

Real runs require a known Workspace. Git URLs, canonical paths, ownership, and current state are validated before work reaches the Worker.

02

Shell and plugins do not receive unlimited authority

The Worker runs tasks through a controlled executor. Plugins are disabled by default and only approved, digest-pinned entries can enter execution.

03

Credentials stay separate from artifacts

Model keys live in an encrypted Vault and never enter task records, screenshots, or repositories. Logs redact sensitive fields while outcomes become controlled artifacts and audit events.

IMPLEMENTED, NOT IMPLIED

Execution boundaries

  • Workspace path and ownership checks
  • Isolated worktrees and containers
  • Hardened Git operations
  • Plugin allowlist and digest pinning
  • Vault, log redaction, and audit retention

Continue exploring

Staging-to-production promotion