Register the workspace before execution
Real runs require a known Workspace. Git URLs, canonical paths, ownership, and current state are validated before work reaches the Worker.
SECURE AGENT EXECUTION
The browser never reaches arbitrary directories on a user's computer. PiGO limits work to registered server-side Git directories and isolated worktrees, with separate controls for tools, paths, plugins, credentials, and release actions.
Real runs require a known Workspace. Git URLs, canonical paths, ownership, and current state are validated before work reaches the Worker.
The Worker runs tasks through a controlled executor. Plugins are disabled by default and only approved, digest-pinned entries can enter execution.
Model keys live in an encrypted Vault and never enter task records, screenshots, or repositories. Logs redact sensitive fields while outcomes become controlled artifacts and audit events.
IMPLEMENTED, NOT IMPLIED