Skip to content

Repository files navigation

safe-mini

License: MITStatus: alphaPython 3.11+

A bounded local-execution substrate with policy guards for mini-swe-agent–style bash-action coding agents.

Fresh worktree copies, scoped HOME, a sanitized environment, and explicit command policies. The built-in executors run commands in the host process context; isolation requires an injected executor boundary.


What this is

safe-mini is the load-bearing runtime substrate for mini-swe-agent–style coding agents that decide one bash command at a time within a budget.

Current and planned consumers:

ConsumerRole
JustAiExplicit, opt-in source adapter over the public runner contract.
local-residentPlanned research harness — benchmark corpus + calibration matrix.

safe-mini is intentionally generic: it does not know about its consumers' domain models. Future projects can ship on top of the same substrate.

What lives here

  • Runner loop — prompt → one bash action → observation → repeat
  • Action protocol parsers — fenced bash block, JSON action object
  • Executor policiesopen / safe / allowlist (and future variants)
  • Observation policiesfull / tail / headtail / structured / structured+raw-tail
  • Worktree provisioner — fresh copy of repo per run, scoped HOME, sanitized PATH
  • Command/path guard — built-in regex policy checks before host-process execution
  • Failure classifier — 7-class taxonomy
  • Run transcript — in-memory per-step records carried in RunResult
  • Canonical typesChunk, Budget, RunResult, FailureClass, ObservationPolicy, ExecutorPolicy
  • AgentRunner Protocol — the contract consumers depend on

Failure taxonomy

ClassMeaning
safety-violationAgent attempted an action the executor policy denied.
action-protocol-violationOutput didn't parse as a valid action.
exhausted-ideasBudget remained but the loop converged without progress.
budget-exhaustedMove or observation budget hit the cap.
context-starvationObservations truncated below decision-relevant detail.
reward-hackingTest passed by means unrelated to the requested change.
embodiment-failureAction ran but didn't produce the expected world-state change.

Two-axis budget

Every run is bounded on TWO axes:

  • Move budget — how many bash actions the agent can execute.
  • Observation budget — how many characters of output the agent can read.

Both are enforced inside the runner. Either axis can independently fire BUDGET_EXHAUSTED.

Installation

Note: safe-mini is in alpha. Not yet on PyPI. Pinning options below.

From git (Phase A — current)

pip install 'safe-mini @ git+https://github.com/JustinJLeopard/safe-mini.git@17c8514c1bf42d3064748400745099ca1723e782'

From source (development)

git clone https://github.com/JustinJLeopard/safe-mini.git
cd safe-mini
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest -q
ruff check safe_mini tests
mypy safe_mini

From PyPI (Phase B — pending stabilization)

pip install safe-mini # not yet published

Status

Current source state: alpha (package metadata 0.1.0). The reference implementation from the pre-public 54-trial calibration study is preserved under reference/ for transparency. The production package under safe_mini/ now includes the concrete SafeMiniRunner, action parser, executor policies, observation handling, worktree provisioning, and integration tests. The injectable executor boundary supports explicit consumers such as JustAi.

This records source integration only. It is not package-install, live-model, productive-runtime, or release evidence.

Empirical baseline (from the lab study, 6 task families × 9 configs × 54 trials):

These are deterministic reference-study results, not proof of host isolation, release readiness, or broad real-model performance.

  • "Open" executor leaked a fake credential 6 / 6 probe runs while still solving the task.
  • "Safe" executor blocked 6 / 6 probes and still solved 6 / 6 tasks.
  • reproduce_first workflow: 2 steps avg vs 3 for inspect_first.
  • headtail and structured observations beat pure tail on noisy output (tail dropped early failure clues).
  • JSON and fenced-bash action protocols equivalent in deterministic tests; live-model malformed-action rate is the open question.

The lab study artifacts:

  • reference/lab_safe_mini_agent.py — the original 270-line single-file agent loop
  • reference/lab_benchmark_tasks.py — the 6-task corpus
  • reference/lab_benchmark_safe_mini.py — the matrix-runner

The production runner components have been factored into this package. The benchmark harness remains separate work for local-resident.

Three-repo architecture

safe-mini is one of three repos:

 ┌─────────────────────────┐ ┌────────────────────────────┐
│ JustAi │ │ local-resident │
│ (orchestrator) │ │ (researcher harness) │
└────────────┬────────────┘ └──────────────┬─────────────┘
│ │
└──────────────┬──────────────────────┘
▼
┌──────────────┐
│ safe-mini │
│ (this repo) │
└──────────────┘

Contributing

This is currently a personal-research-stage project. Issue reports and design discussions welcome via GitHub Issues. PRs accepted after issue-first design review for non-trivial changes.

License

MIT — see LICENSE.

About

Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - JustinJLeopard/safe-mini: Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents. · GitHub
Skip to content

Repository files navigation

safe-mini

License: MITStatus: alphaPython 3.11+

A bounded local-execution substrate with policy guards for mini-swe-agent–style bash-action coding agents.

Fresh worktree copies, scoped HOME, a sanitized environment, and explicit command policies. The built-in executors run commands in the host process context; isolation requires an injected executor boundary.


What this is

safe-mini is the load-bearing runtime substrate for mini-swe-agent–style coding agents that decide one bash command at a time within a budget.

Current and planned consumers:

ConsumerRole
JustAiExplicit, opt-in source adapter over the public runner contract.
local-residentPlanned research harness — benchmark corpus + calibration matrix.

safe-mini is intentionally generic: it does not know about its consumers' domain models. Future projects can ship on top of the same substrate.

What lives here

  • Runner loop — prompt → one bash action → observation → repeat
  • Action protocol parsers — fenced bash block, JSON action object
  • Executor policiesopen / safe / allowlist (and future variants)
  • Observation policiesfull / tail / headtail / structured / structured+raw-tail
  • Worktree provisioner — fresh copy of repo per run, scoped HOME, sanitized PATH
  • Command/path guard — built-in regex policy checks before host-process execution
  • Failure classifier — 7-class taxonomy
  • Run transcript — in-memory per-step records carried in RunResult
  • Canonical typesChunk, Budget, RunResult, FailureClass, ObservationPolicy, ExecutorPolicy
  • AgentRunner Protocol — the contract consumers depend on

Failure taxonomy

ClassMeaning
safety-violationAgent attempted an action the executor policy denied.
action-protocol-violationOutput didn't parse as a valid action.
exhausted-ideasBudget remained but the loop converged without progress.
budget-exhaustedMove or observation budget hit the cap.
context-starvationObservations truncated below decision-relevant detail.
reward-hackingTest passed by means unrelated to the requested change.
embodiment-failureAction ran but didn't produce the expected world-state change.

Two-axis budget

Every run is bounded on TWO axes:

  • Move budget — how many bash actions the agent can execute.
  • Observation budget — how many characters of output the agent can read.

Both are enforced inside the runner. Either axis can independently fire BUDGET_EXHAUSTED.

Installation

Note: safe-mini is in alpha. Not yet on PyPI. Pinning options below.

From git (Phase A — current)

pip install 'safe-mini @ git+https://github.com/JustinJLeopard/safe-mini.git@17c8514c1bf42d3064748400745099ca1723e782'

From source (development)

git clone https://github.com/JustinJLeopard/safe-mini.git
cd safe-mini
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest -q
ruff check safe_mini tests
mypy safe_mini

From PyPI (Phase B — pending stabilization)

pip install safe-mini # not yet published

Status

Current source state: alpha (package metadata 0.1.0). The reference implementation from the pre-public 54-trial calibration study is preserved under reference/ for transparency. The production package under safe_mini/ now includes the concrete SafeMiniRunner, action parser, executor policies, observation handling, worktree provisioning, and integration tests. The injectable executor boundary supports explicit consumers such as JustAi.

This records source integration only. It is not package-install, live-model, productive-runtime, or release evidence.

Empirical baseline (from the lab study, 6 task families × 9 configs × 54 trials):

These are deterministic reference-study results, not proof of host isolation, release readiness, or broad real-model performance.

  • "Open" executor leaked a fake credential 6 / 6 probe runs while still solving the task.
  • "Safe" executor blocked 6 / 6 probes and still solved 6 / 6 tasks.
  • reproduce_first workflow: 2 steps avg vs 3 for inspect_first.
  • headtail and structured observations beat pure tail on noisy output (tail dropped early failure clues).
  • JSON and fenced-bash action protocols equivalent in deterministic tests; live-model malformed-action rate is the open question.

The lab study artifacts:

  • reference/lab_safe_mini_agent.py — the original 270-line single-file agent loop
  • reference/lab_benchmark_tasks.py — the 6-task corpus
  • reference/lab_benchmark_safe_mini.py — the matrix-runner

The production runner components have been factored into this package. The benchmark harness remains separate work for local-resident.

Three-repo architecture

safe-mini is one of three repos:

 ┌─────────────────────────┐ ┌────────────────────────────┐
│ JustAi │ │ local-resident │
│ (orchestrator) │ │ (researcher harness) │
└────────────┬────────────┘ └──────────────┬─────────────┘
│ │
└──────────────┬──────────────────────┘
▼
┌──────────────┐
│ safe-mini │
│ (this repo) │
└──────────────┘

Contributing

This is currently a personal-research-stage project. Issue reports and design discussions welcome via GitHub Issues. PRs accepted after issue-first design review for non-trivial changes.

License

MIT — see LICENSE.

About

Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - JustinJLeopard/safe-mini: Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents. · GitHub
Skip to content

Repository files navigation

safe-mini

License: MITStatus: alphaPython 3.11+

A bounded local-execution substrate with policy guards for mini-swe-agent–style bash-action coding agents.

Fresh worktree copies, scoped HOME, a sanitized environment, and explicit command policies. The built-in executors run commands in the host process context; isolation requires an injected executor boundary.


What this is

safe-mini is the load-bearing runtime substrate for mini-swe-agent–style coding agents that decide one bash command at a time within a budget.

Current and planned consumers:

ConsumerRole
JustAiExplicit, opt-in source adapter over the public runner contract.
local-residentPlanned research harness — benchmark corpus + calibration matrix.

safe-mini is intentionally generic: it does not know about its consumers' domain models. Future projects can ship on top of the same substrate.

What lives here

  • Runner loop — prompt → one bash action → observation → repeat
  • Action protocol parsers — fenced bash block, JSON action object
  • Executor policiesopen / safe / allowlist (and future variants)
  • Observation policiesfull / tail / headtail / structured / structured+raw-tail
  • Worktree provisioner — fresh copy of repo per run, scoped HOME, sanitized PATH
  • Command/path guard — built-in regex policy checks before host-process execution
  • Failure classifier — 7-class taxonomy
  • Run transcript — in-memory per-step records carried in RunResult
  • Canonical typesChunk, Budget, RunResult, FailureClass, ObservationPolicy, ExecutorPolicy
  • AgentRunner Protocol — the contract consumers depend on

Failure taxonomy

ClassMeaning
safety-violationAgent attempted an action the executor policy denied.
action-protocol-violationOutput didn't parse as a valid action.
exhausted-ideasBudget remained but the loop converged without progress.
budget-exhaustedMove or observation budget hit the cap.
context-starvationObservations truncated below decision-relevant detail.
reward-hackingTest passed by means unrelated to the requested change.
embodiment-failureAction ran but didn't produce the expected world-state change.

Two-axis budget

Every run is bounded on TWO axes:

  • Move budget — how many bash actions the agent can execute.
  • Observation budget — how many characters of output the agent can read.

Both are enforced inside the runner. Either axis can independently fire BUDGET_EXHAUSTED.

Installation

Note: safe-mini is in alpha. Not yet on PyPI. Pinning options below.

From git (Phase A — current)

pip install 'safe-mini @ git+https://github.com/JustinJLeopard/safe-mini.git@17c8514c1bf42d3064748400745099ca1723e782'

From source (development)

git clone https://github.com/JustinJLeopard/safe-mini.git
cd safe-mini
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest -q
ruff check safe_mini tests
mypy safe_mini

From PyPI (Phase B — pending stabilization)

pip install safe-mini # not yet published

Status

Current source state: alpha (package metadata 0.1.0). The reference implementation from the pre-public 54-trial calibration study is preserved under reference/ for transparency. The production package under safe_mini/ now includes the concrete SafeMiniRunner, action parser, executor policies, observation handling, worktree provisioning, and integration tests. The injectable executor boundary supports explicit consumers such as JustAi.

This records source integration only. It is not package-install, live-model, productive-runtime, or release evidence.

Empirical baseline (from the lab study, 6 task families × 9 configs × 54 trials):

These are deterministic reference-study results, not proof of host isolation, release readiness, or broad real-model performance.

  • "Open" executor leaked a fake credential 6 / 6 probe runs while still solving the task.
  • "Safe" executor blocked 6 / 6 probes and still solved 6 / 6 tasks.
  • reproduce_first workflow: 2 steps avg vs 3 for inspect_first.
  • headtail and structured observations beat pure tail on noisy output (tail dropped early failure clues).
  • JSON and fenced-bash action protocols equivalent in deterministic tests; live-model malformed-action rate is the open question.

The lab study artifacts:

  • reference/lab_safe_mini_agent.py — the original 270-line single-file agent loop
  • reference/lab_benchmark_tasks.py — the 6-task corpus
  • reference/lab_benchmark_safe_mini.py — the matrix-runner

The production runner components have been factored into this package. The benchmark harness remains separate work for local-resident.

Three-repo architecture

safe-mini is one of three repos:

 ┌─────────────────────────┐ ┌────────────────────────────┐
│ JustAi │ │ local-resident │
│ (orchestrator) │ │ (researcher harness) │
└────────────┬────────────┘ └──────────────┬─────────────┘
│ │
└──────────────┬──────────────────────┘
▼
┌──────────────┐
│ safe-mini │
│ (this repo) │
└──────────────┘

Contributing

This is currently a personal-research-stage project. Issue reports and design discussions welcome via GitHub Issues. PRs accepted after issue-first design review for non-trivial changes.

License

MIT — see LICENSE.

About

Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - JustinJLeopard/safe-mini: Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents. · GitHub
Skip to content

Repository files navigation

safe-mini

License: MITStatus: alphaPython 3.11+

A bounded local-execution substrate with policy guards for mini-swe-agent–style bash-action coding agents.

Fresh worktree copies, scoped HOME, a sanitized environment, and explicit command policies. The built-in executors run commands in the host process context; isolation requires an injected executor boundary.


What this is

safe-mini is the load-bearing runtime substrate for mini-swe-agent–style coding agents that decide one bash command at a time within a budget.

Current and planned consumers:

ConsumerRole
JustAiExplicit, opt-in source adapter over the public runner contract.
local-residentPlanned research harness — benchmark corpus + calibration matrix.

safe-mini is intentionally generic: it does not know about its consumers' domain models. Future projects can ship on top of the same substrate.

What lives here

  • Runner loop — prompt → one bash action → observation → repeat
  • Action protocol parsers — fenced bash block, JSON action object
  • Executor policiesopen / safe / allowlist (and future variants)
  • Observation policiesfull / tail / headtail / structured / structured+raw-tail
  • Worktree provisioner — fresh copy of repo per run, scoped HOME, sanitized PATH
  • Command/path guard — built-in regex policy checks before host-process execution
  • Failure classifier — 7-class taxonomy
  • Run transcript — in-memory per-step records carried in RunResult
  • Canonical typesChunk, Budget, RunResult, FailureClass, ObservationPolicy, ExecutorPolicy
  • AgentRunner Protocol — the contract consumers depend on

Failure taxonomy

ClassMeaning
safety-violationAgent attempted an action the executor policy denied.
action-protocol-violationOutput didn't parse as a valid action.
exhausted-ideasBudget remained but the loop converged without progress.
budget-exhaustedMove or observation budget hit the cap.
context-starvationObservations truncated below decision-relevant detail.
reward-hackingTest passed by means unrelated to the requested change.
embodiment-failureAction ran but didn't produce the expected world-state change.

Two-axis budget

Every run is bounded on TWO axes:

  • Move budget — how many bash actions the agent can execute.
  • Observation budget — how many characters of output the agent can read.

Both are enforced inside the runner. Either axis can independently fire BUDGET_EXHAUSTED.

Installation

Note: safe-mini is in alpha. Not yet on PyPI. Pinning options below.

From git (Phase A — current)

pip install 'safe-mini @ git+https://github.com/JustinJLeopard/safe-mini.git@17c8514c1bf42d3064748400745099ca1723e782'

From source (development)

git clone https://github.com/JustinJLeopard/safe-mini.git
cd safe-mini
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest -q
ruff check safe_mini tests
mypy safe_mini

From PyPI (Phase B — pending stabilization)

pip install safe-mini # not yet published

Status

Current source state: alpha (package metadata 0.1.0). The reference implementation from the pre-public 54-trial calibration study is preserved under reference/ for transparency. The production package under safe_mini/ now includes the concrete SafeMiniRunner, action parser, executor policies, observation handling, worktree provisioning, and integration tests. The injectable executor boundary supports explicit consumers such as JustAi.

This records source integration only. It is not package-install, live-model, productive-runtime, or release evidence.

Empirical baseline (from the lab study, 6 task families × 9 configs × 54 trials):

These are deterministic reference-study results, not proof of host isolation, release readiness, or broad real-model performance.

  • "Open" executor leaked a fake credential 6 / 6 probe runs while still solving the task.
  • "Safe" executor blocked 6 / 6 probes and still solved 6 / 6 tasks.
  • reproduce_first workflow: 2 steps avg vs 3 for inspect_first.
  • headtail and structured observations beat pure tail on noisy output (tail dropped early failure clues).
  • JSON and fenced-bash action protocols equivalent in deterministic tests; live-model malformed-action rate is the open question.

The lab study artifacts:

  • reference/lab_safe_mini_agent.py — the original 270-line single-file agent loop
  • reference/lab_benchmark_tasks.py — the 6-task corpus
  • reference/lab_benchmark_safe_mini.py — the matrix-runner

The production runner components have been factored into this package. The benchmark harness remains separate work for local-resident.

Three-repo architecture

safe-mini is one of three repos:

 ┌─────────────────────────┐ ┌────────────────────────────┐
│ JustAi │ │ local-resident │
│ (orchestrator) │ │ (researcher harness) │
└────────────┬────────────┘ └──────────────┬─────────────┘
│ │
└──────────────┬──────────────────────┘
▼
┌──────────────┐
│ safe-mini │
│ (this repo) │
└──────────────┘

Contributing

This is currently a personal-research-stage project. Issue reports and design discussions welcome via GitHub Issues. PRs accepted after issue-first design review for non-trivial changes.

License

MIT — see LICENSE.

About

Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - JustinJLeopard/safe-mini: Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents. · GitHub
Skip to content

Repository files navigation

safe-mini

License: MITStatus: alphaPython 3.11+

A bounded local-execution substrate with policy guards for mini-swe-agent–style bash-action coding agents.

Fresh worktree copies, scoped HOME, a sanitized environment, and explicit command policies. The built-in executors run commands in the host process context; isolation requires an injected executor boundary.


What this is

safe-mini is the load-bearing runtime substrate for mini-swe-agent–style coding agents that decide one bash command at a time within a budget.

Current and planned consumers:

ConsumerRole
JustAiExplicit, opt-in source adapter over the public runner contract.
local-residentPlanned research harness — benchmark corpus + calibration matrix.

safe-mini is intentionally generic: it does not know about its consumers' domain models. Future projects can ship on top of the same substrate.

What lives here

  • Runner loop — prompt → one bash action → observation → repeat
  • Action protocol parsers — fenced bash block, JSON action object
  • Executor policiesopen / safe / allowlist (and future variants)
  • Observation policiesfull / tail / headtail / structured / structured+raw-tail
  • Worktree provisioner — fresh copy of repo per run, scoped HOME, sanitized PATH
  • Command/path guard — built-in regex policy checks before host-process execution
  • Failure classifier — 7-class taxonomy
  • Run transcript — in-memory per-step records carried in RunResult
  • Canonical typesChunk, Budget, RunResult, FailureClass, ObservationPolicy, ExecutorPolicy
  • AgentRunner Protocol — the contract consumers depend on

Failure taxonomy

ClassMeaning
safety-violationAgent attempted an action the executor policy denied.
action-protocol-violationOutput didn't parse as a valid action.
exhausted-ideasBudget remained but the loop converged without progress.
budget-exhaustedMove or observation budget hit the cap.
context-starvationObservations truncated below decision-relevant detail.
reward-hackingTest passed by means unrelated to the requested change.
embodiment-failureAction ran but didn't produce the expected world-state change.

Two-axis budget

Every run is bounded on TWO axes:

  • Move budget — how many bash actions the agent can execute.
  • Observation budget — how many characters of output the agent can read.

Both are enforced inside the runner. Either axis can independently fire BUDGET_EXHAUSTED.

Installation

Note: safe-mini is in alpha. Not yet on PyPI. Pinning options below.

From git (Phase A — current)

pip install 'safe-mini @ git+https://github.com/JustinJLeopard/safe-mini.git@17c8514c1bf42d3064748400745099ca1723e782'

From source (development)

git clone https://github.com/JustinJLeopard/safe-mini.git
cd safe-mini
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest -q
ruff check safe_mini tests
mypy safe_mini

From PyPI (Phase B — pending stabilization)

pip install safe-mini # not yet published

Status

Current source state: alpha (package metadata 0.1.0). The reference implementation from the pre-public 54-trial calibration study is preserved under reference/ for transparency. The production package under safe_mini/ now includes the concrete SafeMiniRunner, action parser, executor policies, observation handling, worktree provisioning, and integration tests. The injectable executor boundary supports explicit consumers such as JustAi.

This records source integration only. It is not package-install, live-model, productive-runtime, or release evidence.

Empirical baseline (from the lab study, 6 task families × 9 configs × 54 trials):

These are deterministic reference-study results, not proof of host isolation, release readiness, or broad real-model performance.

  • "Open" executor leaked a fake credential 6 / 6 probe runs while still solving the task.
  • "Safe" executor blocked 6 / 6 probes and still solved 6 / 6 tasks.
  • reproduce_first workflow: 2 steps avg vs 3 for inspect_first.
  • headtail and structured observations beat pure tail on noisy output (tail dropped early failure clues).
  • JSON and fenced-bash action protocols equivalent in deterministic tests; live-model malformed-action rate is the open question.

The lab study artifacts:

  • reference/lab_safe_mini_agent.py — the original 270-line single-file agent loop
  • reference/lab_benchmark_tasks.py — the 6-task corpus
  • reference/lab_benchmark_safe_mini.py — the matrix-runner

The production runner components have been factored into this package. The benchmark harness remains separate work for local-resident.

Three-repo architecture

safe-mini is one of three repos:

 ┌─────────────────────────┐ ┌────────────────────────────┐
│ JustAi │ │ local-resident │
│ (orchestrator) │ │ (researcher harness) │
└────────────┬────────────┘ └──────────────┬─────────────┘
│ │
└──────────────┬──────────────────────┘
▼
┌──────────────┐
│ safe-mini │
│ (this repo) │
└──────────────┘

Contributing

This is currently a personal-research-stage project. Issue reports and design discussions welcome via GitHub Issues. PRs accepted after issue-first design review for non-trivial changes.

License

MIT — see LICENSE.

About

Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - JustinJLeopard/safe-mini: Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents. · GitHub
Skip to content

Repository files navigation

safe-mini

License: MITStatus: alphaPython 3.11+

A bounded local-execution substrate with policy guards for mini-swe-agent–style bash-action coding agents.

Fresh worktree copies, scoped HOME, a sanitized environment, and explicit command policies. The built-in executors run commands in the host process context; isolation requires an injected executor boundary.


What this is

safe-mini is the load-bearing runtime substrate for mini-swe-agent–style coding agents that decide one bash command at a time within a budget.

Current and planned consumers:

ConsumerRole
JustAiExplicit, opt-in source adapter over the public runner contract.
local-residentPlanned research harness — benchmark corpus + calibration matrix.

safe-mini is intentionally generic: it does not know about its consumers' domain models. Future projects can ship on top of the same substrate.

What lives here

  • Runner loop — prompt → one bash action → observation → repeat
  • Action protocol parsers — fenced bash block, JSON action object
  • Executor policiesopen / safe / allowlist (and future variants)
  • Observation policiesfull / tail / headtail / structured / structured+raw-tail
  • Worktree provisioner — fresh copy of repo per run, scoped HOME, sanitized PATH
  • Command/path guard — built-in regex policy checks before host-process execution
  • Failure classifier — 7-class taxonomy
  • Run transcript — in-memory per-step records carried in RunResult
  • Canonical typesChunk, Budget, RunResult, FailureClass, ObservationPolicy, ExecutorPolicy
  • AgentRunner Protocol — the contract consumers depend on

Failure taxonomy

ClassMeaning
safety-violationAgent attempted an action the executor policy denied.
action-protocol-violationOutput didn't parse as a valid action.
exhausted-ideasBudget remained but the loop converged without progress.
budget-exhaustedMove or observation budget hit the cap.
context-starvationObservations truncated below decision-relevant detail.
reward-hackingTest passed by means unrelated to the requested change.
embodiment-failureAction ran but didn't produce the expected world-state change.

Two-axis budget

Every run is bounded on TWO axes:

  • Move budget — how many bash actions the agent can execute.
  • Observation budget — how many characters of output the agent can read.

Both are enforced inside the runner. Either axis can independently fire BUDGET_EXHAUSTED.

Installation

Note: safe-mini is in alpha. Not yet on PyPI. Pinning options below.

From git (Phase A — current)

pip install 'safe-mini @ git+https://github.com/JustinJLeopard/safe-mini.git@17c8514c1bf42d3064748400745099ca1723e782'

From source (development)

git clone https://github.com/JustinJLeopard/safe-mini.git
cd safe-mini
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest -q
ruff check safe_mini tests
mypy safe_mini

From PyPI (Phase B — pending stabilization)

pip install safe-mini # not yet published

Status

Current source state: alpha (package metadata 0.1.0). The reference implementation from the pre-public 54-trial calibration study is preserved under reference/ for transparency. The production package under safe_mini/ now includes the concrete SafeMiniRunner, action parser, executor policies, observation handling, worktree provisioning, and integration tests. The injectable executor boundary supports explicit consumers such as JustAi.

This records source integration only. It is not package-install, live-model, productive-runtime, or release evidence.

Empirical baseline (from the lab study, 6 task families × 9 configs × 54 trials):

These are deterministic reference-study results, not proof of host isolation, release readiness, or broad real-model performance.

  • "Open" executor leaked a fake credential 6 / 6 probe runs while still solving the task.
  • "Safe" executor blocked 6 / 6 probes and still solved 6 / 6 tasks.
  • reproduce_first workflow: 2 steps avg vs 3 for inspect_first.
  • headtail and structured observations beat pure tail on noisy output (tail dropped early failure clues).
  • JSON and fenced-bash action protocols equivalent in deterministic tests; live-model malformed-action rate is the open question.

The lab study artifacts:

  • reference/lab_safe_mini_agent.py — the original 270-line single-file agent loop
  • reference/lab_benchmark_tasks.py — the 6-task corpus
  • reference/lab_benchmark_safe_mini.py — the matrix-runner

The production runner components have been factored into this package. The benchmark harness remains separate work for local-resident.

Three-repo architecture

safe-mini is one of three repos:

 ┌─────────────────────────┐ ┌────────────────────────────┐
│ JustAi │ │ local-resident │
│ (orchestrator) │ │ (researcher harness) │
└────────────┬────────────┘ └──────────────┬─────────────┘
│ │
└──────────────┬──────────────────────┘
▼
┌──────────────┐
│ safe-mini │
│ (this repo) │
└──────────────┘

Contributing

This is currently a personal-research-stage project. Issue reports and design discussions welcome via GitHub Issues. PRs accepted after issue-first design review for non-trivial changes.

License

MIT — see LICENSE.

About

Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - JustinJLeopard/safe-mini: Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents. · GitHub
Skip to content

Repository files navigation

safe-mini

License: MITStatus: alphaPython 3.11+

A bounded local-execution substrate with policy guards for mini-swe-agent–style bash-action coding agents.

Fresh worktree copies, scoped HOME, a sanitized environment, and explicit command policies. The built-in executors run commands in the host process context; isolation requires an injected executor boundary.


What this is

safe-mini is the load-bearing runtime substrate for mini-swe-agent–style coding agents that decide one bash command at a time within a budget.

Current and planned consumers:

ConsumerRole
JustAiExplicit, opt-in source adapter over the public runner contract.
local-residentPlanned research harness — benchmark corpus + calibration matrix.

safe-mini is intentionally generic: it does not know about its consumers' domain models. Future projects can ship on top of the same substrate.

What lives here

  • Runner loop — prompt → one bash action → observation → repeat
  • Action protocol parsers — fenced bash block, JSON action object
  • Executor policiesopen / safe / allowlist (and future variants)
  • Observation policiesfull / tail / headtail / structured / structured+raw-tail
  • Worktree provisioner — fresh copy of repo per run, scoped HOME, sanitized PATH
  • Command/path guard — built-in regex policy checks before host-process execution
  • Failure classifier — 7-class taxonomy
  • Run transcript — in-memory per-step records carried in RunResult
  • Canonical typesChunk, Budget, RunResult, FailureClass, ObservationPolicy, ExecutorPolicy
  • AgentRunner Protocol — the contract consumers depend on

Failure taxonomy

ClassMeaning
safety-violationAgent attempted an action the executor policy denied.
action-protocol-violationOutput didn't parse as a valid action.
exhausted-ideasBudget remained but the loop converged without progress.
budget-exhaustedMove or observation budget hit the cap.
context-starvationObservations truncated below decision-relevant detail.
reward-hackingTest passed by means unrelated to the requested change.
embodiment-failureAction ran but didn't produce the expected world-state change.

Two-axis budget

Every run is bounded on TWO axes:

  • Move budget — how many bash actions the agent can execute.
  • Observation budget — how many characters of output the agent can read.

Both are enforced inside the runner. Either axis can independently fire BUDGET_EXHAUSTED.

Installation

Note: safe-mini is in alpha. Not yet on PyPI. Pinning options below.

From git (Phase A — current)

pip install 'safe-mini @ git+https://github.com/JustinJLeopard/safe-mini.git@17c8514c1bf42d3064748400745099ca1723e782'

From source (development)

git clone https://github.com/JustinJLeopard/safe-mini.git
cd safe-mini
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest -q
ruff check safe_mini tests
mypy safe_mini

From PyPI (Phase B — pending stabilization)

pip install safe-mini # not yet published

Status

Current source state: alpha (package metadata 0.1.0). The reference implementation from the pre-public 54-trial calibration study is preserved under reference/ for transparency. The production package under safe_mini/ now includes the concrete SafeMiniRunner, action parser, executor policies, observation handling, worktree provisioning, and integration tests. The injectable executor boundary supports explicit consumers such as JustAi.

This records source integration only. It is not package-install, live-model, productive-runtime, or release evidence.

Empirical baseline (from the lab study, 6 task families × 9 configs × 54 trials):

These are deterministic reference-study results, not proof of host isolation, release readiness, or broad real-model performance.

  • "Open" executor leaked a fake credential 6 / 6 probe runs while still solving the task.
  • "Safe" executor blocked 6 / 6 probes and still solved 6 / 6 tasks.
  • reproduce_first workflow: 2 steps avg vs 3 for inspect_first.
  • headtail and structured observations beat pure tail on noisy output (tail dropped early failure clues).
  • JSON and fenced-bash action protocols equivalent in deterministic tests; live-model malformed-action rate is the open question.

The lab study artifacts:

  • reference/lab_safe_mini_agent.py — the original 270-line single-file agent loop
  • reference/lab_benchmark_tasks.py — the 6-task corpus
  • reference/lab_benchmark_safe_mini.py — the matrix-runner

The production runner components have been factored into this package. The benchmark harness remains separate work for local-resident.

Three-repo architecture

safe-mini is one of three repos:

 ┌─────────────────────────┐ ┌────────────────────────────┐
│ JustAi │ │ local-resident │
│ (orchestrator) │ │ (researcher harness) │
└────────────┬────────────┘ └──────────────┬─────────────┘
│ │
└──────────────┬──────────────────────┘
▼
┌──────────────┐
│ safe-mini │
│ (this repo) │
└──────────────┘

Contributing

This is currently a personal-research-stage project. Issue reports and design discussions welcome via GitHub Issues. PRs accepted after issue-first design review for non-trivial changes.

License

MIT — see LICENSE.

About

Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - JustinJLeopard/safe-mini: Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents. · GitHub
Skip to content

Repository files navigation

safe-mini

License: MITStatus: alphaPython 3.11+

A bounded local-execution substrate with policy guards for mini-swe-agent–style bash-action coding agents.

Fresh worktree copies, scoped HOME, a sanitized environment, and explicit command policies. The built-in executors run commands in the host process context; isolation requires an injected executor boundary.


What this is

safe-mini is the load-bearing runtime substrate for mini-swe-agent–style coding agents that decide one bash command at a time within a budget.

Current and planned consumers:

ConsumerRole
JustAiExplicit, opt-in source adapter over the public runner contract.
local-residentPlanned research harness — benchmark corpus + calibration matrix.

safe-mini is intentionally generic: it does not know about its consumers' domain models. Future projects can ship on top of the same substrate.

What lives here

  • Runner loop — prompt → one bash action → observation → repeat
  • Action protocol parsers — fenced bash block, JSON action object
  • Executor policiesopen / safe / allowlist (and future variants)
  • Observation policiesfull / tail / headtail / structured / structured+raw-tail
  • Worktree provisioner — fresh copy of repo per run, scoped HOME, sanitized PATH
  • Command/path guard — built-in regex policy checks before host-process execution
  • Failure classifier — 7-class taxonomy
  • Run transcript — in-memory per-step records carried in RunResult
  • Canonical typesChunk, Budget, RunResult, FailureClass, ObservationPolicy, ExecutorPolicy
  • AgentRunner Protocol — the contract consumers depend on

Failure taxonomy

ClassMeaning
safety-violationAgent attempted an action the executor policy denied.
action-protocol-violationOutput didn't parse as a valid action.
exhausted-ideasBudget remained but the loop converged without progress.
budget-exhaustedMove or observation budget hit the cap.
context-starvationObservations truncated below decision-relevant detail.
reward-hackingTest passed by means unrelated to the requested change.
embodiment-failureAction ran but didn't produce the expected world-state change.

Two-axis budget

Every run is bounded on TWO axes:

  • Move budget — how many bash actions the agent can execute.
  • Observation budget — how many characters of output the agent can read.

Both are enforced inside the runner. Either axis can independently fire BUDGET_EXHAUSTED.

Installation

Note: safe-mini is in alpha. Not yet on PyPI. Pinning options below.

From git (Phase A — current)

pip install 'safe-mini @ git+https://github.com/JustinJLeopard/safe-mini.git@17c8514c1bf42d3064748400745099ca1723e782'

From source (development)

git clone https://github.com/JustinJLeopard/safe-mini.git
cd safe-mini
python3 -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
pytest -q
ruff check safe_mini tests
mypy safe_mini

From PyPI (Phase B — pending stabilization)

pip install safe-mini # not yet published

Status

Current source state: alpha (package metadata 0.1.0). The reference implementation from the pre-public 54-trial calibration study is preserved under reference/ for transparency. The production package under safe_mini/ now includes the concrete SafeMiniRunner, action parser, executor policies, observation handling, worktree provisioning, and integration tests. The injectable executor boundary supports explicit consumers such as JustAi.

This records source integration only. It is not package-install, live-model, productive-runtime, or release evidence.

Empirical baseline (from the lab study, 6 task families × 9 configs × 54 trials):

These are deterministic reference-study results, not proof of host isolation, release readiness, or broad real-model performance.

  • "Open" executor leaked a fake credential 6 / 6 probe runs while still solving the task.
  • "Safe" executor blocked 6 / 6 probes and still solved 6 / 6 tasks.
  • reproduce_first workflow: 2 steps avg vs 3 for inspect_first.
  • headtail and structured observations beat pure tail on noisy output (tail dropped early failure clues).
  • JSON and fenced-bash action protocols equivalent in deterministic tests; live-model malformed-action rate is the open question.

The lab study artifacts:

  • reference/lab_safe_mini_agent.py — the original 270-line single-file agent loop
  • reference/lab_benchmark_tasks.py — the 6-task corpus
  • reference/lab_benchmark_safe_mini.py — the matrix-runner

The production runner components have been factored into this package. The benchmark harness remains separate work for local-resident.

Three-repo architecture

safe-mini is one of three repos:

 ┌─────────────────────────┐ ┌────────────────────────────┐
│ JustAi │ │ local-resident │
│ (orchestrator) │ │ (researcher harness) │
└────────────┬────────────┘ └──────────────┬─────────────┘
│ │
└──────────────┬──────────────────────┘
▼
┌──────────────┐
│ safe-mini │
│ (this repo) │
└──────────────┘

Contributing

This is currently a personal-research-stage project. Issue reports and design discussions welcome via GitHub Issues. PRs accepted after issue-first design review for non-trivial changes.

License

MIT — see LICENSE.

About

Safe-by-construction local execution substrate for mini-swe-agent-style bash-action coding agents.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages