Latest commit

History

1,830 Commits

Folders and files

NameName
Last commit message
Last commit date

Workcell

CIDocsSecurity

Workcell runs coding agents in a bounded local runtime on Apple Silicon macOS. The strict runtime uses a hardened container in a dedicated Colima VM. Workcell supports Tier 1 adapters for Codex, Claude Code, GitHub Copilot CLI, and Gemini. Each adapter uses the native provider control plane. Provider configuration is not the security boundary. Workcell does not support --agent antigravity.

Use Workcell when a team needs local agents and an explicit runtime boundary. The safe path does not pass through the host home, keychain, provider state, or local sockets.

Why Workcell

  • keep the runtime boundary explicit: dedicated VM, hardened container, minimal mounts
  • keep provider adapters native: one shared boundary, thin provider-specific control-plane mapping
  • keep the normal publication workflow on the host: signed commits, signed-range verification, and GitHub publication stay out of Tier 1
  • keep publication authority explicit: credential injection can give a session publication authority
  • keep verification paths nonroot by default: runtime and validator images default to a named unprivileged workcell user, while repo-mounted validation lanes pass explicit caller UID/GID and isolated writable state, with a synthesized isolated home when the caller UID has no passwd entry in the image
  • keep lower-assurance paths visible: development, package mutation, transcripts, and breakglass are labeled instead of implied

How it compares

ApproachPrimary boundaryProvider-native control planeNormal publication pathLower-assurance paths called out
Host-native provider CLIhost user sessionyeshost user sessionrarely
Generic container wrappercontainer only, often mixed with host stateoften partialvariesoften unclear
Workcell strictdedicated Colima VM plus hardened containeryesseparate host workflowyes

Project status

  • v1.0.2 is the first published 1.0 release.
  • the published deprecation policy governs the frozen v1 public contract
  • Apple Silicon macOS hosts only today; Linux and Windows are not currently supported as launch hosts
  • local host-launched runtime first; cloud-facing paths today are the preview-only remote_vm/aws-ec2-ssm/compat and remote_vm/gcp-vm/compat broker plans, and their live smokes remain certification-only
  • CLI surfaces for Codex, Claude, Copilot, and upstream-served Gemini auth modes plus host-side detached session control and inspection commands
  • GitHub Copilot CLI uses explicit copilot_github_token staging through reviewed host-side inputs, converts it to a host-mounted token handoff outside mounted provider state, moves it through a transient runtime handoff file, and exports its value as COPILOT_GITHUB_TOKEN only to the managed Copilot child process, with isolated COPILOT_HOME and COPILOT_CACHE_HOME; host gh auth, Copilot provider state (~/.copilot, ~/.config/github-copilot, ~/.cache/github-copilot), keychains, and whole-home state are not safe-path inputs
  • Google Antigravity CLI is queued behind the same evidence bar and remains planned/fail-closed until Workcell ships adapter, auth, quickstart, deterministic evidence, and live certification together
  • GitHub-hosted CI verifies repo shape, reproducibility, release posture, and secretless runtime behavior
  • On Apple Silicon macos-26 and macos-15, hosted CI verifies bundle installation, launcher-link removal, and man-page-link removal. It also verifies Homebrew installation and formula removal.
  • the real macOS Colima boundary is still a local operator exercise because GitHub-hosted Linux runners cannot prove it
  • the canonical host support boundary lives in policy/host-support-matrix.tsv, and --doctor / --inspect emit matching host and support_matrix_* lines
  • Workcell does not yet ship a centralized enterprise policy, inventory, or analytics plane; team rollout today relies on distributing reviewed host-side files

The changelog identifies each breaking change. The roadmap identifies future work.

Community

  • use GitHub Discussions for usage questions, operator workflow notes, and open-ended design conversations
  • use GitHub issues for confirmed bugs and concrete feature requests
  • use SECURITY.md for security-sensitive reports

See SUPPORT.md, CONTRIBUTING.md, and CITATION.cff for the contributor and operator contract.

Choose your path

Pick the entry point that matches what you need. Each is a short labeled list of links; the full index is in the Docs map below.

5-minute path

Install Workcell, create the host-side auth policy, inspect the derived posture, then launch. ./scripts/install.sh below assumes you are in a verified or source tree; to install a tagged release instead, use the verified one-command path ./scripts/install-release.sh --version vX.Y.Z (see Install for the tag clone, signature checks, and the optional --attestation gate).

./scripts/install.sh
workcell auth init
workcell auth set \
--agent codex \
--credential codex_auth \
--source /Users/example/.config/workcell/codex-auth.json
workcell --agent codex --doctor --workspace /path/to/repo
workcell --agent codex --inspect --workspace /path/to/repo
workcell --agent codex --workspace /path/to/repo

For Copilot, use the provider-specific credential instead of the Codex auth file:

workcell auth set \
--agent copilot \
--credential copilot_github_token \
--source /Users/example/.config/workcell/copilot-github-token.txt
workcell --agent copilot --workspace /path/to/repo

Claude and Gemini use the same managed launch shape after their provider-specific auth is configured:

workcell --agent claude --workspace /path/to/repo
workcell --agent gemini --workspace /path/to/repo

See docs/getting-started.md for the release install path and provider-specific onboarding. For team rollout patterns on today's local-first product, see docs/enterprise-rollout.md. Use policy/host-support-matrix.tsv to interpret the host support boundary that --doctor and --inspect report.

Install

On Apple Silicon macOS, the recommended path is the one-command verified release install, which downloads a tagged release, verifies its cosign signature and digest fail-closed before any bundle code runs, and only then installs. install-release.sh is not a standalone release asset. Get it from the repository through TLS transport, not from the unverified bundle. Then authenticate the selected revision with the signed-tag check:

brew install cosign git gnupg # verifier tools must exist before verification runs (macOS ships neither gnupg nor, on a clean host, git)
git clone --branch vX.Y.Z --depth 1 https://github.com/omkhar/workcell.git
cd workcell
git tag -v vX.Y.Z # verify the tag signature before running the installer
./scripts/install-release.sh --version vX.Y.Z

Clone the tag (--branch vX.Y.Z), not the mutable default branch: the pre-trust installer runs before any release verification, so it must come from the signed, immutable release commit rather than whatever main currently holds. git tag -v authenticates that commit against the maintainer signing key before you execute the installer — import and confirm the key fingerprint from SECURITY.md first.

The verifier tools (cosign, and git/gnupg for the clone and tag check) must already be installed, because verification runs before the bundle installer that provides the other host packages (colima, docker, go); pass -- --no-install-deps for a launcher-only install. For an additional GitHub attestation check, append --attestation — that step needs gh installed and authenticated (brew install gh && gh auth login) and network access. To verify and install straight from the release page without a clone, use the manual cosign flow in docs/getting-started.md; if you already have a verified, unpacked release tree, run ./scripts/install.sh from inside it.

For the Homebrew formula asset, the source checkout path, and the full host requirements, see docs/install.md.

If you suspect an incident, preserve all available evidence before you run workcell --gc. See docs/incident-response.md. To reclaim stale runtime, cache, and temporary state without an uninstall, run workcell --gc. It removes aged transient session-audit.* scratch, not durable session records.

Run ./scripts/uninstall.sh --dry-run before you uninstall Workcell. Its output is the authoritative list. The uninstall command removes the launcher link and the managed state under ~/.local/state/workcell. It also removes Workcell-managed Colima profiles and caches. Workcell-managed profiles and caches use legacy workcell-* names or current wcl-* names. The command does not remove shared packages or unrelated profiles.

The uninstall command does not reach a custom WORKCELL_STATE_ROOT or XDG_STATE_HOME. Remove that custom state separately. After a Homebrew formula install, brew uninstall workcell removes only the formula. Also run ./scripts/uninstall.sh from a bundle or checkout to remove the runtime state. See docs/install-lifecycle.md.

Command reference

The supported commands at a glance; follow the links for the full behavior and options.

Docs map

Operator reference

TopicFile
Install and requirementsdocs/install.md
Onboarding and authdocs/onboarding-and-auth.md
Provider quickstartsdocs/provider-quickstarts.md
Mode mapdocs/mode-map.md
Safe-path expectationsdocs/safe-path-expectations.md
Release posturedocs/release-posture.md

Product and security docs

TopicFile
Getting starteddocs/getting-started.md
Support tiersdocs/support-tiers.md
Diagnostics and support matrixdocs/diagnostics-and-support-matrix.md
Security invariantsdocs/invariants.md
Threat modeldocs/threat-model.md
CI/CD threat modeldocs/ci-threat-model.md
OWASP agentic mappingdocs/owasp-agentic-mapping.md
Provider matrixdocs/provider-matrix.md
Provider bootstrap matrixdocs/provider-bootstrap-matrix.md
Adapter control planesdocs/adapter-control-planes.md
Injection policydocs/injection-policy.md
Validation coveragedocs/validation-scenarios.md
Requirements validationdocs/requirements-validation.md
Scenario gapsdocs/scenario-gaps.md
Use-case coveragedocs/use-case-matrix.md
Session supervisor designdocs/workcell-session-supervisor-design.md
Managed workstation contractdocs/managed-workstation-contract.md
Enterprise evidence baselinedocs/enterprise-evidence-baseline.md
Enterprise rolloutdocs/enterprise-rollout.md
Host expansion readinessdocs/host-expansion-readiness.md
AWS EC2 SSM previewdocs/aws-ec2-ssm-preview.md
GCP VM previewdocs/gcp-vm-preview.md
Provenance and signingdocs/provenance.md
GitHub automationdocs/github-workflows.md
Artifact retention policydocs/retention-policy.md

Project docs

TopicFile
Contributor workflowCONTRIBUTING.md
SupportSUPPORT.md
Code of conductCODE_OF_CONDUCT.md
GovernanceGOVERNANCE.md
MaintainersMAINTAINERS.md
RoadmapROADMAP.md
ChangelogCHANGELOG.md
Security reportingSECURITY.md
Stability and exit-code contractdocs/stability-contract.md
Software engineering practicesdocs/software-engineering-practices.md
Standards watchlistdocs/standards-watchlist.md
Documentation languagedocs/documentation-language.md

Repository layout

  • runtime/: VM and container boundary implementation
  • policy/: shared contract layer and hosted-control policy
  • adapters/: provider-native baselines for Codex, Claude, Copilot, and Gemini, plus fail-closed Antigravity planning scaffolding
  • cmd/: host-side and runtime-side Go entrypoints (the workcell-* binaries)
  • internal/: shared Go packages backing the cmd/ binaries
  • scripts/: launcher, validation, release, audit, and bootstrap entrypoints
  • verify/: invariant-oriented verification material
  • man/: workcell.1 manpage
  • tests/: scenario manifests and fixtures
  • tools/: developer tooling (markdownlint, validator image)
  • docs/: user-facing design, quickstarts, install, and release docs
  • workflows/: implementation notes such as adapter porting guidance

License

Workcell is licensed under Apache-2.0. See LICENSE.

About

Bounded local runtime and policy boundary for coding agents

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

20 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

1,830 Commits

Folders and files

NameName
Last commit message
Last commit date

Workcell

CIDocsSecurity

Workcell runs coding agents in a bounded local runtime on Apple Silicon macOS. The strict runtime uses a hardened container in a dedicated Colima VM. Workcell supports Tier 1 adapters for Codex, Claude Code, GitHub Copilot CLI, and Gemini. Each adapter uses the native provider control plane. Provider configuration is not the security boundary. Workcell does not support --agent antigravity.

Use Workcell when a team needs local agents and an explicit runtime boundary. The safe path does not pass through the host home, keychain, provider state, or local sockets.

Why Workcell

  • keep the runtime boundary explicit: dedicated VM, hardened container, minimal mounts
  • keep provider adapters native: one shared boundary, thin provider-specific control-plane mapping
  • keep the normal publication workflow on the host: signed commits, signed-range verification, and GitHub publication stay out of Tier 1
  • keep publication authority explicit: credential injection can give a session publication authority
  • keep verification paths nonroot by default: runtime and validator images default to a named unprivileged workcell user, while repo-mounted validation lanes pass explicit caller UID/GID and isolated writable state, with a synthesized isolated home when the caller UID has no passwd entry in the image
  • keep lower-assurance paths visible: development, package mutation, transcripts, and breakglass are labeled instead of implied

How it compares

ApproachPrimary boundaryProvider-native control planeNormal publication pathLower-assurance paths called out
Host-native provider CLIhost user sessionyeshost user sessionrarely
Generic container wrappercontainer only, often mixed with host stateoften partialvariesoften unclear
Workcell strictdedicated Colima VM plus hardened containeryesseparate host workflowyes

Project status

  • v1.0.2 is the first published 1.0 release.
  • the published deprecation policy governs the frozen v1 public contract
  • Apple Silicon macOS hosts only today; Linux and Windows are not currently supported as launch hosts
  • local host-launched runtime first; cloud-facing paths today are the preview-only remote_vm/aws-ec2-ssm/compat and remote_vm/gcp-vm/compat broker plans, and their live smokes remain certification-only
  • CLI surfaces for Codex, Claude, Copilot, and upstream-served Gemini auth modes plus host-side detached session control and inspection commands
  • GitHub Copilot CLI uses explicit copilot_github_token staging through reviewed host-side inputs, converts it to a host-mounted token handoff outside mounted provider state, moves it through a transient runtime handoff file, and exports its value as COPILOT_GITHUB_TOKEN only to the managed Copilot child process, with isolated COPILOT_HOME and COPILOT_CACHE_HOME; host gh auth, Copilot provider state (~/.copilot, ~/.config/github-copilot, ~/.cache/github-copilot), keychains, and whole-home state are not safe-path inputs
  • Google Antigravity CLI is queued behind the same evidence bar and remains planned/fail-closed until Workcell ships adapter, auth, quickstart, deterministic evidence, and live certification together
  • GitHub-hosted CI verifies repo shape, reproducibility, release posture, and secretless runtime behavior
  • On Apple Silicon macos-26 and macos-15, hosted CI verifies bundle installation, launcher-link removal, and man-page-link removal. It also verifies Homebrew installation and formula removal.
  • the real macOS Colima boundary is still a local operator exercise because GitHub-hosted Linux runners cannot prove it
  • the canonical host support boundary lives in policy/host-support-matrix.tsv, and --doctor / --inspect emit matching host and support_matrix_* lines
  • Workcell does not yet ship a centralized enterprise policy, inventory, or analytics plane; team rollout today relies on distributing reviewed host-side files

The changelog identifies each breaking change. The roadmap identifies future work.

Community

  • use GitHub Discussions for usage questions, operator workflow notes, and open-ended design conversations
  • use GitHub issues for confirmed bugs and concrete feature requests
  • use SECURITY.md for security-sensitive reports

See SUPPORT.md, CONTRIBUTING.md, and CITATION.cff for the contributor and operator contract.

Choose your path

Pick the entry point that matches what you need. Each is a short labeled list of links; the full index is in the Docs map below.

5-minute path

Install Workcell, create the host-side auth policy, inspect the derived posture, then launch. ./scripts/install.sh below assumes you are in a verified or source tree; to install a tagged release instead, use the verified one-command path ./scripts/install-release.sh --version vX.Y.Z (see Install for the tag clone, signature checks, and the optional --attestation gate).

./scripts/install.sh
workcell auth init
workcell auth set \
--agent codex \
--credential codex_auth \
--source /Users/example/.config/workcell/codex-auth.json
workcell --agent codex --doctor --workspace /path/to/repo
workcell --agent codex --inspect --workspace /path/to/repo
workcell --agent codex --workspace /path/to/repo

For Copilot, use the provider-specific credential instead of the Codex auth file:

workcell auth set \
--agent copilot \
--credential copilot_github_token \
--source /Users/example/.config/workcell/copilot-github-token.txt
workcell --agent copilot --workspace /path/to/repo

Claude and Gemini use the same managed launch shape after their provider-specific auth is configured:

workcell --agent claude --workspace /path/to/repo
workcell --agent gemini --workspace /path/to/repo

See docs/getting-started.md for the release install path and provider-specific onboarding. For team rollout patterns on today's local-first product, see docs/enterprise-rollout.md. Use policy/host-support-matrix.tsv to interpret the host support boundary that --doctor and --inspect report.

Install

On Apple Silicon macOS, the recommended path is the one-command verified release install, which downloads a tagged release, verifies its cosign signature and digest fail-closed before any bundle code runs, and only then installs. install-release.sh is not a standalone release asset. Get it from the repository through TLS transport, not from the unverified bundle. Then authenticate the selected revision with the signed-tag check:

brew install cosign git gnupg # verifier tools must exist before verification runs (macOS ships neither gnupg nor, on a clean host, git)
git clone --branch vX.Y.Z --depth 1 https://github.com/omkhar/workcell.git
cd workcell
git tag -v vX.Y.Z # verify the tag signature before running the installer
./scripts/install-release.sh --version vX.Y.Z

Clone the tag (--branch vX.Y.Z), not the mutable default branch: the pre-trust installer runs before any release verification, so it must come from the signed, immutable release commit rather than whatever main currently holds. git tag -v authenticates that commit against the maintainer signing key before you execute the installer — import and confirm the key fingerprint from SECURITY.md first.

The verifier tools (cosign, and git/gnupg for the clone and tag check) must already be installed, because verification runs before the bundle installer that provides the other host packages (colima, docker, go); pass -- --no-install-deps for a launcher-only install. For an additional GitHub attestation check, append --attestation — that step needs gh installed and authenticated (brew install gh && gh auth login) and network access. To verify and install straight from the release page without a clone, use the manual cosign flow in docs/getting-started.md; if you already have a verified, unpacked release tree, run ./scripts/install.sh from inside it.

For the Homebrew formula asset, the source checkout path, and the full host requirements, see docs/install.md.

If you suspect an incident, preserve all available evidence before you run workcell --gc. See docs/incident-response.md. To reclaim stale runtime, cache, and temporary state without an uninstall, run workcell --gc. It removes aged transient session-audit.* scratch, not durable session records.

Run ./scripts/uninstall.sh --dry-run before you uninstall Workcell. Its output is the authoritative list. The uninstall command removes the launcher link and the managed state under ~/.local/state/workcell. It also removes Workcell-managed Colima profiles and caches. Workcell-managed profiles and caches use legacy workcell-* names or current wcl-* names. The command does not remove shared packages or unrelated profiles.

The uninstall command does not reach a custom WORKCELL_STATE_ROOT or XDG_STATE_HOME. Remove that custom state separately. After a Homebrew formula install, brew uninstall workcell removes only the formula. Also run ./scripts/uninstall.sh from a bundle or checkout to remove the runtime state. See docs/install-lifecycle.md.

Command reference

The supported commands at a glance; follow the links for the full behavior and options.

Docs map

Operator reference

TopicFile
Install and requirementsdocs/install.md
Onboarding and authdocs/onboarding-and-auth.md
Provider quickstartsdocs/provider-quickstarts.md
Mode mapdocs/mode-map.md
Safe-path expectationsdocs/safe-path-expectations.md
Release posturedocs/release-posture.md

Product and security docs

TopicFile
Getting starteddocs/getting-started.md
Support tiersdocs/support-tiers.md
Diagnostics and support matrixdocs/diagnostics-and-support-matrix.md
Security invariantsdocs/invariants.md
Threat modeldocs/threat-model.md
CI/CD threat modeldocs/ci-threat-model.md
OWASP agentic mappingdocs/owasp-agentic-mapping.md
Provider matrixdocs/provider-matrix.md
Provider bootstrap matrixdocs/provider-bootstrap-matrix.md
Adapter control planesdocs/adapter-control-planes.md
Injection policydocs/injection-policy.md
Validation coveragedocs/validation-scenarios.md
Requirements validationdocs/requirements-validation.md
Scenario gapsdocs/scenario-gaps.md
Use-case coveragedocs/use-case-matrix.md
Session supervisor designdocs/workcell-session-supervisor-design.md
Managed workstation contractdocs/managed-workstation-contract.md
Enterprise evidence baselinedocs/enterprise-evidence-baseline.md
Enterprise rolloutdocs/enterprise-rollout.md
Host expansion readinessdocs/host-expansion-readiness.md
AWS EC2 SSM previewdocs/aws-ec2-ssm-preview.md
GCP VM previewdocs/gcp-vm-preview.md
Provenance and signingdocs/provenance.md
GitHub automationdocs/github-workflows.md
Artifact retention policydocs/retention-policy.md

Project docs

TopicFile
Contributor workflowCONTRIBUTING.md
SupportSUPPORT.md
Code of conductCODE_OF_CONDUCT.md
GovernanceGOVERNANCE.md
MaintainersMAINTAINERS.md
RoadmapROADMAP.md
ChangelogCHANGELOG.md
Security reportingSECURITY.md
Stability and exit-code contractdocs/stability-contract.md
Software engineering practicesdocs/software-engineering-practices.md
Standards watchlistdocs/standards-watchlist.md
Documentation languagedocs/documentation-language.md

Repository layout

  • runtime/: VM and container boundary implementation
  • policy/: shared contract layer and hosted-control policy
  • adapters/: provider-native baselines for Codex, Claude, Copilot, and Gemini, plus fail-closed Antigravity planning scaffolding
  • cmd/: host-side and runtime-side Go entrypoints (the workcell-* binaries)
  • internal/: shared Go packages backing the cmd/ binaries
  • scripts/: launcher, validation, release, audit, and bootstrap entrypoints
  • verify/: invariant-oriented verification material
  • man/: workcell.1 manpage
  • tests/: scenario manifests and fixtures
  • tools/: developer tooling (markdownlint, validator image)
  • docs/: user-facing design, quickstarts, install, and release docs
  • workflows/: implementation notes such as adapter porting guidance

License

Workcell is licensed under Apache-2.0. See LICENSE.

About

Bounded local runtime and policy boundary for coding agents

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

20 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,830 Commits

Folders and files

NameName
Last commit message
Last commit date

Workcell

CIDocsSecurity

Workcell runs coding agents in a bounded local runtime on Apple Silicon macOS. The strict runtime uses a hardened container in a dedicated Colima VM. Workcell supports Tier 1 adapters for Codex, Claude Code, GitHub Copilot CLI, and Gemini. Each adapter uses the native provider control plane. Provider configuration is not the security boundary. Workcell does not support --agent antigravity.

Use Workcell when a team needs local agents and an explicit runtime boundary. The safe path does not pass through the host home, keychain, provider state, or local sockets.

Why Workcell

  • keep the runtime boundary explicit: dedicated VM, hardened container, minimal mounts
  • keep provider adapters native: one shared boundary, thin provider-specific control-plane mapping
  • keep the normal publication workflow on the host: signed commits, signed-range verification, and GitHub publication stay out of Tier 1
  • keep publication authority explicit: credential injection can give a session publication authority
  • keep verification paths nonroot by default: runtime and validator images default to a named unprivileged workcell user, while repo-mounted validation lanes pass explicit caller UID/GID and isolated writable state, with a synthesized isolated home when the caller UID has no passwd entry in the image
  • keep lower-assurance paths visible: development, package mutation, transcripts, and breakglass are labeled instead of implied

How it compares

ApproachPrimary boundaryProvider-native control planeNormal publication pathLower-assurance paths called out
Host-native provider CLIhost user sessionyeshost user sessionrarely
Generic container wrappercontainer only, often mixed with host stateoften partialvariesoften unclear
Workcell strictdedicated Colima VM plus hardened containeryesseparate host workflowyes

Project status

  • v1.0.2 is the first published 1.0 release.
  • the published deprecation policy governs the frozen v1 public contract
  • Apple Silicon macOS hosts only today; Linux and Windows are not currently supported as launch hosts
  • local host-launched runtime first; cloud-facing paths today are the preview-only remote_vm/aws-ec2-ssm/compat and remote_vm/gcp-vm/compat broker plans, and their live smokes remain certification-only
  • CLI surfaces for Codex, Claude, Copilot, and upstream-served Gemini auth modes plus host-side detached session control and inspection commands
  • GitHub Copilot CLI uses explicit copilot_github_token staging through reviewed host-side inputs, converts it to a host-mounted token handoff outside mounted provider state, moves it through a transient runtime handoff file, and exports its value as COPILOT_GITHUB_TOKEN only to the managed Copilot child process, with isolated COPILOT_HOME and COPILOT_CACHE_HOME; host gh auth, Copilot provider state (~/.copilot, ~/.config/github-copilot, ~/.cache/github-copilot), keychains, and whole-home state are not safe-path inputs
  • Google Antigravity CLI is queued behind the same evidence bar and remains planned/fail-closed until Workcell ships adapter, auth, quickstart, deterministic evidence, and live certification together
  • GitHub-hosted CI verifies repo shape, reproducibility, release posture, and secretless runtime behavior
  • On Apple Silicon macos-26 and macos-15, hosted CI verifies bundle installation, launcher-link removal, and man-page-link removal. It also verifies Homebrew installation and formula removal.
  • the real macOS Colima boundary is still a local operator exercise because GitHub-hosted Linux runners cannot prove it
  • the canonical host support boundary lives in policy/host-support-matrix.tsv, and --doctor / --inspect emit matching host and support_matrix_* lines
  • Workcell does not yet ship a centralized enterprise policy, inventory, or analytics plane; team rollout today relies on distributing reviewed host-side files

The changelog identifies each breaking change. The roadmap identifies future work.

Community

  • use GitHub Discussions for usage questions, operator workflow notes, and open-ended design conversations
  • use GitHub issues for confirmed bugs and concrete feature requests
  • use SECURITY.md for security-sensitive reports

See SUPPORT.md, CONTRIBUTING.md, and CITATION.cff for the contributor and operator contract.

Choose your path

Pick the entry point that matches what you need. Each is a short labeled list of links; the full index is in the Docs map below.

5-minute path

Install Workcell, create the host-side auth policy, inspect the derived posture, then launch. ./scripts/install.sh below assumes you are in a verified or source tree; to install a tagged release instead, use the verified one-command path ./scripts/install-release.sh --version vX.Y.Z (see Install for the tag clone, signature checks, and the optional --attestation gate).

./scripts/install.sh
workcell auth init
workcell auth set \
--agent codex \
--credential codex_auth \
--source /Users/example/.config/workcell/codex-auth.json
workcell --agent codex --doctor --workspace /path/to/repo
workcell --agent codex --inspect --workspace /path/to/repo
workcell --agent codex --workspace /path/to/repo

For Copilot, use the provider-specific credential instead of the Codex auth file:

workcell auth set \
--agent copilot \
--credential copilot_github_token \
--source /Users/example/.config/workcell/copilot-github-token.txt
workcell --agent copilot --workspace /path/to/repo

Claude and Gemini use the same managed launch shape after their provider-specific auth is configured:

workcell --agent claude --workspace /path/to/repo
workcell --agent gemini --workspace /path/to/repo

See docs/getting-started.md for the release install path and provider-specific onboarding. For team rollout patterns on today's local-first product, see docs/enterprise-rollout.md. Use policy/host-support-matrix.tsv to interpret the host support boundary that --doctor and --inspect report.

Install

On Apple Silicon macOS, the recommended path is the one-command verified release install, which downloads a tagged release, verifies its cosign signature and digest fail-closed before any bundle code runs, and only then installs. install-release.sh is not a standalone release asset. Get it from the repository through TLS transport, not from the unverified bundle. Then authenticate the selected revision with the signed-tag check:

brew install cosign git gnupg # verifier tools must exist before verification runs (macOS ships neither gnupg nor, on a clean host, git)
git clone --branch vX.Y.Z --depth 1 https://github.com/omkhar/workcell.git
cd workcell
git tag -v vX.Y.Z # verify the tag signature before running the installer
./scripts/install-release.sh --version vX.Y.Z

Clone the tag (--branch vX.Y.Z), not the mutable default branch: the pre-trust installer runs before any release verification, so it must come from the signed, immutable release commit rather than whatever main currently holds. git tag -v authenticates that commit against the maintainer signing key before you execute the installer — import and confirm the key fingerprint from SECURITY.md first.

The verifier tools (cosign, and git/gnupg for the clone and tag check) must already be installed, because verification runs before the bundle installer that provides the other host packages (colima, docker, go); pass -- --no-install-deps for a launcher-only install. For an additional GitHub attestation check, append --attestation — that step needs gh installed and authenticated (brew install gh && gh auth login) and network access. To verify and install straight from the release page without a clone, use the manual cosign flow in docs/getting-started.md; if you already have a verified, unpacked release tree, run ./scripts/install.sh from inside it.

For the Homebrew formula asset, the source checkout path, and the full host requirements, see docs/install.md.

If you suspect an incident, preserve all available evidence before you run workcell --gc. See docs/incident-response.md. To reclaim stale runtime, cache, and temporary state without an uninstall, run workcell --gc. It removes aged transient session-audit.* scratch, not durable session records.

Run ./scripts/uninstall.sh --dry-run before you uninstall Workcell. Its output is the authoritative list. The uninstall command removes the launcher link and the managed state under ~/.local/state/workcell. It also removes Workcell-managed Colima profiles and caches. Workcell-managed profiles and caches use legacy workcell-* names or current wcl-* names. The command does not remove shared packages or unrelated profiles.

The uninstall command does not reach a custom WORKCELL_STATE_ROOT or XDG_STATE_HOME. Remove that custom state separately. After a Homebrew formula install, brew uninstall workcell removes only the formula. Also run ./scripts/uninstall.sh from a bundle or checkout to remove the runtime state. See docs/install-lifecycle.md.

Command reference

The supported commands at a glance; follow the links for the full behavior and options.

Docs map

Operator reference

TopicFile
Install and requirementsdocs/install.md
Onboarding and authdocs/onboarding-and-auth.md
Provider quickstartsdocs/provider-quickstarts.md
Mode mapdocs/mode-map.md
Safe-path expectationsdocs/safe-path-expectations.md
Release posturedocs/release-posture.md

Product and security docs

TopicFile
Getting starteddocs/getting-started.md
Support tiersdocs/support-tiers.md
Diagnostics and support matrixdocs/diagnostics-and-support-matrix.md
Security invariantsdocs/invariants.md
Threat modeldocs/threat-model.md
CI/CD threat modeldocs/ci-threat-model.md
OWASP agentic mappingdocs/owasp-agentic-mapping.md
Provider matrixdocs/provider-matrix.md
Provider bootstrap matrixdocs/provider-bootstrap-matrix.md
Adapter control planesdocs/adapter-control-planes.md
Injection policydocs/injection-policy.md
Validation coveragedocs/validation-scenarios.md
Requirements validationdocs/requirements-validation.md
Scenario gapsdocs/scenario-gaps.md
Use-case coveragedocs/use-case-matrix.md
Session supervisor designdocs/workcell-session-supervisor-design.md
Managed workstation contractdocs/managed-workstation-contract.md
Enterprise evidence baselinedocs/enterprise-evidence-baseline.md
Enterprise rolloutdocs/enterprise-rollout.md
Host expansion readinessdocs/host-expansion-readiness.md
AWS EC2 SSM previewdocs/aws-ec2-ssm-preview.md
GCP VM previewdocs/gcp-vm-preview.md
Provenance and signingdocs/provenance.md
GitHub automationdocs/github-workflows.md
Artifact retention policydocs/retention-policy.md

Project docs

TopicFile
Contributor workflowCONTRIBUTING.md
SupportSUPPORT.md
Code of conductCODE_OF_CONDUCT.md
GovernanceGOVERNANCE.md
MaintainersMAINTAINERS.md
RoadmapROADMAP.md
ChangelogCHANGELOG.md
Security reportingSECURITY.md
Stability and exit-code contractdocs/stability-contract.md
Software engineering practicesdocs/software-engineering-practices.md
Standards watchlistdocs/standards-watchlist.md
Documentation languagedocs/documentation-language.md

Repository layout

  • runtime/: VM and container boundary implementation
  • policy/: shared contract layer and hosted-control policy
  • adapters/: provider-native baselines for Codex, Claude, Copilot, and Gemini, plus fail-closed Antigravity planning scaffolding
  • cmd/: host-side and runtime-side Go entrypoints (the workcell-* binaries)
  • internal/: shared Go packages backing the cmd/ binaries
  • scripts/: launcher, validation, release, audit, and bootstrap entrypoints
  • verify/: invariant-oriented verification material
  • man/: workcell.1 manpage
  • tests/: scenario manifests and fixtures
  • tools/: developer tooling (markdownlint, validator image)
  • docs/: user-facing design, quickstarts, install, and release docs
  • workflows/: implementation notes such as adapter porting guidance

License

Workcell is licensed under Apache-2.0. See LICENSE.

About

Bounded local runtime and policy boundary for coding agents

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

20 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,830 Commits

Folders and files

NameName
Last commit message
Last commit date

Workcell

CIDocsSecurity

Workcell runs coding agents in a bounded local runtime on Apple Silicon macOS. The strict runtime uses a hardened container in a dedicated Colima VM. Workcell supports Tier 1 adapters for Codex, Claude Code, GitHub Copilot CLI, and Gemini. Each adapter uses the native provider control plane. Provider configuration is not the security boundary. Workcell does not support --agent antigravity.

Use Workcell when a team needs local agents and an explicit runtime boundary. The safe path does not pass through the host home, keychain, provider state, or local sockets.

Why Workcell

  • keep the runtime boundary explicit: dedicated VM, hardened container, minimal mounts
  • keep provider adapters native: one shared boundary, thin provider-specific control-plane mapping
  • keep the normal publication workflow on the host: signed commits, signed-range verification, and GitHub publication stay out of Tier 1
  • keep publication authority explicit: credential injection can give a session publication authority
  • keep verification paths nonroot by default: runtime and validator images default to a named unprivileged workcell user, while repo-mounted validation lanes pass explicit caller UID/GID and isolated writable state, with a synthesized isolated home when the caller UID has no passwd entry in the image
  • keep lower-assurance paths visible: development, package mutation, transcripts, and breakglass are labeled instead of implied

How it compares

ApproachPrimary boundaryProvider-native control planeNormal publication pathLower-assurance paths called out
Host-native provider CLIhost user sessionyeshost user sessionrarely
Generic container wrappercontainer only, often mixed with host stateoften partialvariesoften unclear
Workcell strictdedicated Colima VM plus hardened containeryesseparate host workflowyes

Project status

  • v1.0.2 is the first published 1.0 release.
  • the published deprecation policy governs the frozen v1 public contract
  • Apple Silicon macOS hosts only today; Linux and Windows are not currently supported as launch hosts
  • local host-launched runtime first; cloud-facing paths today are the preview-only remote_vm/aws-ec2-ssm/compat and remote_vm/gcp-vm/compat broker plans, and their live smokes remain certification-only
  • CLI surfaces for Codex, Claude, Copilot, and upstream-served Gemini auth modes plus host-side detached session control and inspection commands
  • GitHub Copilot CLI uses explicit copilot_github_token staging through reviewed host-side inputs, converts it to a host-mounted token handoff outside mounted provider state, moves it through a transient runtime handoff file, and exports its value as COPILOT_GITHUB_TOKEN only to the managed Copilot child process, with isolated COPILOT_HOME and COPILOT_CACHE_HOME; host gh auth, Copilot provider state (~/.copilot, ~/.config/github-copilot, ~/.cache/github-copilot), keychains, and whole-home state are not safe-path inputs
  • Google Antigravity CLI is queued behind the same evidence bar and remains planned/fail-closed until Workcell ships adapter, auth, quickstart, deterministic evidence, and live certification together
  • GitHub-hosted CI verifies repo shape, reproducibility, release posture, and secretless runtime behavior
  • On Apple Silicon macos-26 and macos-15, hosted CI verifies bundle installation, launcher-link removal, and man-page-link removal. It also verifies Homebrew installation and formula removal.
  • the real macOS Colima boundary is still a local operator exercise because GitHub-hosted Linux runners cannot prove it
  • the canonical host support boundary lives in policy/host-support-matrix.tsv, and --doctor / --inspect emit matching host and support_matrix_* lines
  • Workcell does not yet ship a centralized enterprise policy, inventory, or analytics plane; team rollout today relies on distributing reviewed host-side files

The changelog identifies each breaking change. The roadmap identifies future work.

Community

  • use GitHub Discussions for usage questions, operator workflow notes, and open-ended design conversations
  • use GitHub issues for confirmed bugs and concrete feature requests
  • use SECURITY.md for security-sensitive reports

See SUPPORT.md, CONTRIBUTING.md, and CITATION.cff for the contributor and operator contract.

Choose your path

Pick the entry point that matches what you need. Each is a short labeled list of links; the full index is in the Docs map below.

5-minute path

Install Workcell, create the host-side auth policy, inspect the derived posture, then launch. ./scripts/install.sh below assumes you are in a verified or source tree; to install a tagged release instead, use the verified one-command path ./scripts/install-release.sh --version vX.Y.Z (see Install for the tag clone, signature checks, and the optional --attestation gate).

./scripts/install.sh
workcell auth init
workcell auth set \
--agent codex \
--credential codex_auth \
--source /Users/example/.config/workcell/codex-auth.json
workcell --agent codex --doctor --workspace /path/to/repo
workcell --agent codex --inspect --workspace /path/to/repo
workcell --agent codex --workspace /path/to/repo

For Copilot, use the provider-specific credential instead of the Codex auth file:

workcell auth set \
--agent copilot \
--credential copilot_github_token \
--source /Users/example/.config/workcell/copilot-github-token.txt
workcell --agent copilot --workspace /path/to/repo

Claude and Gemini use the same managed launch shape after their provider-specific auth is configured:

workcell --agent claude --workspace /path/to/repo
workcell --agent gemini --workspace /path/to/repo

See docs/getting-started.md for the release install path and provider-specific onboarding. For team rollout patterns on today's local-first product, see docs/enterprise-rollout.md. Use policy/host-support-matrix.tsv to interpret the host support boundary that --doctor and --inspect report.

Install

On Apple Silicon macOS, the recommended path is the one-command verified release install, which downloads a tagged release, verifies its cosign signature and digest fail-closed before any bundle code runs, and only then installs. install-release.sh is not a standalone release asset. Get it from the repository through TLS transport, not from the unverified bundle. Then authenticate the selected revision with the signed-tag check:

brew install cosign git gnupg # verifier tools must exist before verification runs (macOS ships neither gnupg nor, on a clean host, git)
git clone --branch vX.Y.Z --depth 1 https://github.com/omkhar/workcell.git
cd workcell
git tag -v vX.Y.Z # verify the tag signature before running the installer
./scripts/install-release.sh --version vX.Y.Z

Clone the tag (--branch vX.Y.Z), not the mutable default branch: the pre-trust installer runs before any release verification, so it must come from the signed, immutable release commit rather than whatever main currently holds. git tag -v authenticates that commit against the maintainer signing key before you execute the installer — import and confirm the key fingerprint from SECURITY.md first.

The verifier tools (cosign, and git/gnupg for the clone and tag check) must already be installed, because verification runs before the bundle installer that provides the other host packages (colima, docker, go); pass -- --no-install-deps for a launcher-only install. For an additional GitHub attestation check, append --attestation — that step needs gh installed and authenticated (brew install gh && gh auth login) and network access. To verify and install straight from the release page without a clone, use the manual cosign flow in docs/getting-started.md; if you already have a verified, unpacked release tree, run ./scripts/install.sh from inside it.

For the Homebrew formula asset, the source checkout path, and the full host requirements, see docs/install.md.

If you suspect an incident, preserve all available evidence before you run workcell --gc. See docs/incident-response.md. To reclaim stale runtime, cache, and temporary state without an uninstall, run workcell --gc. It removes aged transient session-audit.* scratch, not durable session records.

Run ./scripts/uninstall.sh --dry-run before you uninstall Workcell. Its output is the authoritative list. The uninstall command removes the launcher link and the managed state under ~/.local/state/workcell. It also removes Workcell-managed Colima profiles and caches. Workcell-managed profiles and caches use legacy workcell-* names or current wcl-* names. The command does not remove shared packages or unrelated profiles.

The uninstall command does not reach a custom WORKCELL_STATE_ROOT or XDG_STATE_HOME. Remove that custom state separately. After a Homebrew formula install, brew uninstall workcell removes only the formula. Also run ./scripts/uninstall.sh from a bundle or checkout to remove the runtime state. See docs/install-lifecycle.md.

Command reference

The supported commands at a glance; follow the links for the full behavior and options.

Docs map

Operator reference

TopicFile
Install and requirementsdocs/install.md
Onboarding and authdocs/onboarding-and-auth.md
Provider quickstartsdocs/provider-quickstarts.md
Mode mapdocs/mode-map.md
Safe-path expectationsdocs/safe-path-expectations.md
Release posturedocs/release-posture.md

Product and security docs

TopicFile
Getting starteddocs/getting-started.md
Support tiersdocs/support-tiers.md
Diagnostics and support matrixdocs/diagnostics-and-support-matrix.md
Security invariantsdocs/invariants.md
Threat modeldocs/threat-model.md
CI/CD threat modeldocs/ci-threat-model.md
OWASP agentic mappingdocs/owasp-agentic-mapping.md
Provider matrixdocs/provider-matrix.md
Provider bootstrap matrixdocs/provider-bootstrap-matrix.md
Adapter control planesdocs/adapter-control-planes.md
Injection policydocs/injection-policy.md
Validation coveragedocs/validation-scenarios.md
Requirements validationdocs/requirements-validation.md
Scenario gapsdocs/scenario-gaps.md
Use-case coveragedocs/use-case-matrix.md
Session supervisor designdocs/workcell-session-supervisor-design.md
Managed workstation contractdocs/managed-workstation-contract.md
Enterprise evidence baselinedocs/enterprise-evidence-baseline.md
Enterprise rolloutdocs/enterprise-rollout.md
Host expansion readinessdocs/host-expansion-readiness.md
AWS EC2 SSM previewdocs/aws-ec2-ssm-preview.md
GCP VM previewdocs/gcp-vm-preview.md
Provenance and signingdocs/provenance.md
GitHub automationdocs/github-workflows.md
Artifact retention policydocs/retention-policy.md

Project docs

TopicFile
Contributor workflowCONTRIBUTING.md
SupportSUPPORT.md
Code of conductCODE_OF_CONDUCT.md
GovernanceGOVERNANCE.md
MaintainersMAINTAINERS.md
RoadmapROADMAP.md
ChangelogCHANGELOG.md
Security reportingSECURITY.md
Stability and exit-code contractdocs/stability-contract.md
Software engineering practicesdocs/software-engineering-practices.md
Standards watchlistdocs/standards-watchlist.md
Documentation languagedocs/documentation-language.md

Repository layout

  • runtime/: VM and container boundary implementation
  • policy/: shared contract layer and hosted-control policy
  • adapters/: provider-native baselines for Codex, Claude, Copilot, and Gemini, plus fail-closed Antigravity planning scaffolding
  • cmd/: host-side and runtime-side Go entrypoints (the workcell-* binaries)
  • internal/: shared Go packages backing the cmd/ binaries
  • scripts/: launcher, validation, release, audit, and bootstrap entrypoints
  • verify/: invariant-oriented verification material
  • man/: workcell.1 manpage
  • tests/: scenario manifests and fixtures
  • tools/: developer tooling (markdownlint, validator image)
  • docs/: user-facing design, quickstarts, install, and release docs
  • workflows/: implementation notes such as adapter porting guidance

License

Workcell is licensed under Apache-2.0. See LICENSE.

About

Bounded local runtime and policy boundary for coding agents

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

20 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

1,830 Commits

Folders and files

NameName
Last commit message
Last commit date

Workcell

CIDocsSecurity

Workcell runs coding agents in a bounded local runtime on Apple Silicon macOS. The strict runtime uses a hardened container in a dedicated Colima VM. Workcell supports Tier 1 adapters for Codex, Claude Code, GitHub Copilot CLI, and Gemini. Each adapter uses the native provider control plane. Provider configuration is not the security boundary. Workcell does not support --agent antigravity.

Use Workcell when a team needs local agents and an explicit runtime boundary. The safe path does not pass through the host home, keychain, provider state, or local sockets.

Why Workcell

  • keep the runtime boundary explicit: dedicated VM, hardened container, minimal mounts
  • keep provider adapters native: one shared boundary, thin provider-specific control-plane mapping
  • keep the normal publication workflow on the host: signed commits, signed-range verification, and GitHub publication stay out of Tier 1
  • keep publication authority explicit: credential injection can give a session publication authority
  • keep verification paths nonroot by default: runtime and validator images default to a named unprivileged workcell user, while repo-mounted validation lanes pass explicit caller UID/GID and isolated writable state, with a synthesized isolated home when the caller UID has no passwd entry in the image
  • keep lower-assurance paths visible: development, package mutation, transcripts, and breakglass are labeled instead of implied

How it compares

ApproachPrimary boundaryProvider-native control planeNormal publication pathLower-assurance paths called out
Host-native provider CLIhost user sessionyeshost user sessionrarely
Generic container wrappercontainer only, often mixed with host stateoften partialvariesoften unclear
Workcell strictdedicated Colima VM plus hardened containeryesseparate host workflowyes

Project status

  • v1.0.2 is the first published 1.0 release.
  • the published deprecation policy governs the frozen v1 public contract
  • Apple Silicon macOS hosts only today; Linux and Windows are not currently supported as launch hosts
  • local host-launched runtime first; cloud-facing paths today are the preview-only remote_vm/aws-ec2-ssm/compat and remote_vm/gcp-vm/compat broker plans, and their live smokes remain certification-only
  • CLI surfaces for Codex, Claude, Copilot, and upstream-served Gemini auth modes plus host-side detached session control and inspection commands
  • GitHub Copilot CLI uses explicit copilot_github_token staging through reviewed host-side inputs, converts it to a host-mounted token handoff outside mounted provider state, moves it through a transient runtime handoff file, and exports its value as COPILOT_GITHUB_TOKEN only to the managed Copilot child process, with isolated COPILOT_HOME and COPILOT_CACHE_HOME; host gh auth, Copilot provider state (~/.copilot, ~/.config/github-copilot, ~/.cache/github-copilot), keychains, and whole-home state are not safe-path inputs
  • Google Antigravity CLI is queued behind the same evidence bar and remains planned/fail-closed until Workcell ships adapter, auth, quickstart, deterministic evidence, and live certification together
  • GitHub-hosted CI verifies repo shape, reproducibility, release posture, and secretless runtime behavior
  • On Apple Silicon macos-26 and macos-15, hosted CI verifies bundle installation, launcher-link removal, and man-page-link removal. It also verifies Homebrew installation and formula removal.
  • the real macOS Colima boundary is still a local operator exercise because GitHub-hosted Linux runners cannot prove it
  • the canonical host support boundary lives in policy/host-support-matrix.tsv, and --doctor / --inspect emit matching host and support_matrix_* lines
  • Workcell does not yet ship a centralized enterprise policy, inventory, or analytics plane; team rollout today relies on distributing reviewed host-side files

The changelog identifies each breaking change. The roadmap identifies future work.

Community

  • use GitHub Discussions for usage questions, operator workflow notes, and open-ended design conversations
  • use GitHub issues for confirmed bugs and concrete feature requests
  • use SECURITY.md for security-sensitive reports

See SUPPORT.md, CONTRIBUTING.md, and CITATION.cff for the contributor and operator contract.

Choose your path

Pick the entry point that matches what you need. Each is a short labeled list of links; the full index is in the Docs map below.

5-minute path

Install Workcell, create the host-side auth policy, inspect the derived posture, then launch. ./scripts/install.sh below assumes you are in a verified or source tree; to install a tagged release instead, use the verified one-command path ./scripts/install-release.sh --version vX.Y.Z (see Install for the tag clone, signature checks, and the optional --attestation gate).

./scripts/install.sh
workcell auth init
workcell auth set \
--agent codex \
--credential codex_auth \
--source /Users/example/.config/workcell/codex-auth.json
workcell --agent codex --doctor --workspace /path/to/repo
workcell --agent codex --inspect --workspace /path/to/repo
workcell --agent codex --workspace /path/to/repo

For Copilot, use the provider-specific credential instead of the Codex auth file:

workcell auth set \
--agent copilot \
--credential copilot_github_token \
--source /Users/example/.config/workcell/copilot-github-token.txt
workcell --agent copilot --workspace /path/to/repo

Claude and Gemini use the same managed launch shape after their provider-specific auth is configured:

workcell --agent claude --workspace /path/to/repo
workcell --agent gemini --workspace /path/to/repo

See docs/getting-started.md for the release install path and provider-specific onboarding. For team rollout patterns on today's local-first product, see docs/enterprise-rollout.md. Use policy/host-support-matrix.tsv to interpret the host support boundary that --doctor and --inspect report.

Install

On Apple Silicon macOS, the recommended path is the one-command verified release install, which downloads a tagged release, verifies its cosign signature and digest fail-closed before any bundle code runs, and only then installs. install-release.sh is not a standalone release asset. Get it from the repository through TLS transport, not from the unverified bundle. Then authenticate the selected revision with the signed-tag check:

brew install cosign git gnupg # verifier tools must exist before verification runs (macOS ships neither gnupg nor, on a clean host, git)
git clone --branch vX.Y.Z --depth 1 https://github.com/omkhar/workcell.git
cd workcell
git tag -v vX.Y.Z # verify the tag signature before running the installer
./scripts/install-release.sh --version vX.Y.Z

Clone the tag (--branch vX.Y.Z), not the mutable default branch: the pre-trust installer runs before any release verification, so it must come from the signed, immutable release commit rather than whatever main currently holds. git tag -v authenticates that commit against the maintainer signing key before you execute the installer — import and confirm the key fingerprint from SECURITY.md first.

The verifier tools (cosign, and git/gnupg for the clone and tag check) must already be installed, because verification runs before the bundle installer that provides the other host packages (colima, docker, go); pass -- --no-install-deps for a launcher-only install. For an additional GitHub attestation check, append --attestation — that step needs gh installed and authenticated (brew install gh && gh auth login) and network access. To verify and install straight from the release page without a clone, use the manual cosign flow in docs/getting-started.md; if you already have a verified, unpacked release tree, run ./scripts/install.sh from inside it.

For the Homebrew formula asset, the source checkout path, and the full host requirements, see docs/install.md.

If you suspect an incident, preserve all available evidence before you run workcell --gc. See docs/incident-response.md. To reclaim stale runtime, cache, and temporary state without an uninstall, run workcell --gc. It removes aged transient session-audit.* scratch, not durable session records.

Run ./scripts/uninstall.sh --dry-run before you uninstall Workcell. Its output is the authoritative list. The uninstall command removes the launcher link and the managed state under ~/.local/state/workcell. It also removes Workcell-managed Colima profiles and caches. Workcell-managed profiles and caches use legacy workcell-* names or current wcl-* names. The command does not remove shared packages or unrelated profiles.

The uninstall command does not reach a custom WORKCELL_STATE_ROOT or XDG_STATE_HOME. Remove that custom state separately. After a Homebrew formula install, brew uninstall workcell removes only the formula. Also run ./scripts/uninstall.sh from a bundle or checkout to remove the runtime state. See docs/install-lifecycle.md.

Command reference

The supported commands at a glance; follow the links for the full behavior and options.

Docs map

Operator reference

TopicFile
Install and requirementsdocs/install.md
Onboarding and authdocs/onboarding-and-auth.md
Provider quickstartsdocs/provider-quickstarts.md
Mode mapdocs/mode-map.md
Safe-path expectationsdocs/safe-path-expectations.md
Release posturedocs/release-posture.md

Product and security docs

TopicFile
Getting starteddocs/getting-started.md
Support tiersdocs/support-tiers.md
Diagnostics and support matrixdocs/diagnostics-and-support-matrix.md
Security invariantsdocs/invariants.md
Threat modeldocs/threat-model.md
CI/CD threat modeldocs/ci-threat-model.md
OWASP agentic mappingdocs/owasp-agentic-mapping.md
Provider matrixdocs/provider-matrix.md
Provider bootstrap matrixdocs/provider-bootstrap-matrix.md
Adapter control planesdocs/adapter-control-planes.md
Injection policydocs/injection-policy.md
Validation coveragedocs/validation-scenarios.md
Requirements validationdocs/requirements-validation.md
Scenario gapsdocs/scenario-gaps.md
Use-case coveragedocs/use-case-matrix.md
Session supervisor designdocs/workcell-session-supervisor-design.md
Managed workstation contractdocs/managed-workstation-contract.md
Enterprise evidence baselinedocs/enterprise-evidence-baseline.md
Enterprise rolloutdocs/enterprise-rollout.md
Host expansion readinessdocs/host-expansion-readiness.md
AWS EC2 SSM previewdocs/aws-ec2-ssm-preview.md
GCP VM previewdocs/gcp-vm-preview.md
Provenance and signingdocs/provenance.md
GitHub automationdocs/github-workflows.md
Artifact retention policydocs/retention-policy.md

Project docs

TopicFile
Contributor workflowCONTRIBUTING.md
SupportSUPPORT.md
Code of conductCODE_OF_CONDUCT.md
GovernanceGOVERNANCE.md
MaintainersMAINTAINERS.md
RoadmapROADMAP.md
ChangelogCHANGELOG.md
Security reportingSECURITY.md
Stability and exit-code contractdocs/stability-contract.md
Software engineering practicesdocs/software-engineering-practices.md
Standards watchlistdocs/standards-watchlist.md
Documentation languagedocs/documentation-language.md

Repository layout

  • runtime/: VM and container boundary implementation
  • policy/: shared contract layer and hosted-control policy
  • adapters/: provider-native baselines for Codex, Claude, Copilot, and Gemini, plus fail-closed Antigravity planning scaffolding
  • cmd/: host-side and runtime-side Go entrypoints (the workcell-* binaries)
  • internal/: shared Go packages backing the cmd/ binaries
  • scripts/: launcher, validation, release, audit, and bootstrap entrypoints
  • verify/: invariant-oriented verification material
  • man/: workcell.1 manpage
  • tests/: scenario manifests and fixtures
  • tools/: developer tooling (markdownlint, validator image)
  • docs/: user-facing design, quickstarts, install, and release docs
  • workflows/: implementation notes such as adapter porting guidance

License

Workcell is licensed under Apache-2.0. See LICENSE.

About

Bounded local runtime and policy boundary for coding agents

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

20 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,830 Commits

Folders and files

NameName
Last commit message
Last commit date

Workcell

CIDocsSecurity

Workcell runs coding agents in a bounded local runtime on Apple Silicon macOS. The strict runtime uses a hardened container in a dedicated Colima VM. Workcell supports Tier 1 adapters for Codex, Claude Code, GitHub Copilot CLI, and Gemini. Each adapter uses the native provider control plane. Provider configuration is not the security boundary. Workcell does not support --agent antigravity.

Use Workcell when a team needs local agents and an explicit runtime boundary. The safe path does not pass through the host home, keychain, provider state, or local sockets.

Why Workcell

  • keep the runtime boundary explicit: dedicated VM, hardened container, minimal mounts
  • keep provider adapters native: one shared boundary, thin provider-specific control-plane mapping
  • keep the normal publication workflow on the host: signed commits, signed-range verification, and GitHub publication stay out of Tier 1
  • keep publication authority explicit: credential injection can give a session publication authority
  • keep verification paths nonroot by default: runtime and validator images default to a named unprivileged workcell user, while repo-mounted validation lanes pass explicit caller UID/GID and isolated writable state, with a synthesized isolated home when the caller UID has no passwd entry in the image
  • keep lower-assurance paths visible: development, package mutation, transcripts, and breakglass are labeled instead of implied

How it compares

ApproachPrimary boundaryProvider-native control planeNormal publication pathLower-assurance paths called out
Host-native provider CLIhost user sessionyeshost user sessionrarely
Generic container wrappercontainer only, often mixed with host stateoften partialvariesoften unclear
Workcell strictdedicated Colima VM plus hardened containeryesseparate host workflowyes

Project status

  • v1.0.2 is the first published 1.0 release.
  • the published deprecation policy governs the frozen v1 public contract
  • Apple Silicon macOS hosts only today; Linux and Windows are not currently supported as launch hosts
  • local host-launched runtime first; cloud-facing paths today are the preview-only remote_vm/aws-ec2-ssm/compat and remote_vm/gcp-vm/compat broker plans, and their live smokes remain certification-only
  • CLI surfaces for Codex, Claude, Copilot, and upstream-served Gemini auth modes plus host-side detached session control and inspection commands
  • GitHub Copilot CLI uses explicit copilot_github_token staging through reviewed host-side inputs, converts it to a host-mounted token handoff outside mounted provider state, moves it through a transient runtime handoff file, and exports its value as COPILOT_GITHUB_TOKEN only to the managed Copilot child process, with isolated COPILOT_HOME and COPILOT_CACHE_HOME; host gh auth, Copilot provider state (~/.copilot, ~/.config/github-copilot, ~/.cache/github-copilot), keychains, and whole-home state are not safe-path inputs
  • Google Antigravity CLI is queued behind the same evidence bar and remains planned/fail-closed until Workcell ships adapter, auth, quickstart, deterministic evidence, and live certification together
  • GitHub-hosted CI verifies repo shape, reproducibility, release posture, and secretless runtime behavior
  • On Apple Silicon macos-26 and macos-15, hosted CI verifies bundle installation, launcher-link removal, and man-page-link removal. It also verifies Homebrew installation and formula removal.
  • the real macOS Colima boundary is still a local operator exercise because GitHub-hosted Linux runners cannot prove it
  • the canonical host support boundary lives in policy/host-support-matrix.tsv, and --doctor / --inspect emit matching host and support_matrix_* lines
  • Workcell does not yet ship a centralized enterprise policy, inventory, or analytics plane; team rollout today relies on distributing reviewed host-side files

The changelog identifies each breaking change. The roadmap identifies future work.

Community

  • use GitHub Discussions for usage questions, operator workflow notes, and open-ended design conversations
  • use GitHub issues for confirmed bugs and concrete feature requests
  • use SECURITY.md for security-sensitive reports

See SUPPORT.md, CONTRIBUTING.md, and CITATION.cff for the contributor and operator contract.

Choose your path

Pick the entry point that matches what you need. Each is a short labeled list of links; the full index is in the Docs map below.

5-minute path

Install Workcell, create the host-side auth policy, inspect the derived posture, then launch. ./scripts/install.sh below assumes you are in a verified or source tree; to install a tagged release instead, use the verified one-command path ./scripts/install-release.sh --version vX.Y.Z (see Install for the tag clone, signature checks, and the optional --attestation gate).

./scripts/install.sh
workcell auth init
workcell auth set \
--agent codex \
--credential codex_auth \
--source /Users/example/.config/workcell/codex-auth.json
workcell --agent codex --doctor --workspace /path/to/repo
workcell --agent codex --inspect --workspace /path/to/repo
workcell --agent codex --workspace /path/to/repo

For Copilot, use the provider-specific credential instead of the Codex auth file:

workcell auth set \
--agent copilot \
--credential copilot_github_token \
--source /Users/example/.config/workcell/copilot-github-token.txt
workcell --agent copilot --workspace /path/to/repo

Claude and Gemini use the same managed launch shape after their provider-specific auth is configured:

workcell --agent claude --workspace /path/to/repo
workcell --agent gemini --workspace /path/to/repo

See docs/getting-started.md for the release install path and provider-specific onboarding. For team rollout patterns on today's local-first product, see docs/enterprise-rollout.md. Use policy/host-support-matrix.tsv to interpret the host support boundary that --doctor and --inspect report.

Install

On Apple Silicon macOS, the recommended path is the one-command verified release install, which downloads a tagged release, verifies its cosign signature and digest fail-closed before any bundle code runs, and only then installs. install-release.sh is not a standalone release asset. Get it from the repository through TLS transport, not from the unverified bundle. Then authenticate the selected revision with the signed-tag check:

brew install cosign git gnupg # verifier tools must exist before verification runs (macOS ships neither gnupg nor, on a clean host, git)
git clone --branch vX.Y.Z --depth 1 https://github.com/omkhar/workcell.git
cd workcell
git tag -v vX.Y.Z # verify the tag signature before running the installer
./scripts/install-release.sh --version vX.Y.Z

Clone the tag (--branch vX.Y.Z), not the mutable default branch: the pre-trust installer runs before any release verification, so it must come from the signed, immutable release commit rather than whatever main currently holds. git tag -v authenticates that commit against the maintainer signing key before you execute the installer — import and confirm the key fingerprint from SECURITY.md first.

The verifier tools (cosign, and git/gnupg for the clone and tag check) must already be installed, because verification runs before the bundle installer that provides the other host packages (colima, docker, go); pass -- --no-install-deps for a launcher-only install. For an additional GitHub attestation check, append --attestation — that step needs gh installed and authenticated (brew install gh && gh auth login) and network access. To verify and install straight from the release page without a clone, use the manual cosign flow in docs/getting-started.md; if you already have a verified, unpacked release tree, run ./scripts/install.sh from inside it.

For the Homebrew formula asset, the source checkout path, and the full host requirements, see docs/install.md.

If you suspect an incident, preserve all available evidence before you run workcell --gc. See docs/incident-response.md. To reclaim stale runtime, cache, and temporary state without an uninstall, run workcell --gc. It removes aged transient session-audit.* scratch, not durable session records.

Run ./scripts/uninstall.sh --dry-run before you uninstall Workcell. Its output is the authoritative list. The uninstall command removes the launcher link and the managed state under ~/.local/state/workcell. It also removes Workcell-managed Colima profiles and caches. Workcell-managed profiles and caches use legacy workcell-* names or current wcl-* names. The command does not remove shared packages or unrelated profiles.

The uninstall command does not reach a custom WORKCELL_STATE_ROOT or XDG_STATE_HOME. Remove that custom state separately. After a Homebrew formula install, brew uninstall workcell removes only the formula. Also run ./scripts/uninstall.sh from a bundle or checkout to remove the runtime state. See docs/install-lifecycle.md.

Command reference

The supported commands at a glance; follow the links for the full behavior and options.

Docs map

Operator reference

TopicFile
Install and requirementsdocs/install.md
Onboarding and authdocs/onboarding-and-auth.md
Provider quickstartsdocs/provider-quickstarts.md
Mode mapdocs/mode-map.md
Safe-path expectationsdocs/safe-path-expectations.md
Release posturedocs/release-posture.md

Product and security docs

TopicFile
Getting starteddocs/getting-started.md
Support tiersdocs/support-tiers.md
Diagnostics and support matrixdocs/diagnostics-and-support-matrix.md
Security invariantsdocs/invariants.md
Threat modeldocs/threat-model.md
CI/CD threat modeldocs/ci-threat-model.md
OWASP agentic mappingdocs/owasp-agentic-mapping.md
Provider matrixdocs/provider-matrix.md
Provider bootstrap matrixdocs/provider-bootstrap-matrix.md
Adapter control planesdocs/adapter-control-planes.md
Injection policydocs/injection-policy.md
Validation coveragedocs/validation-scenarios.md
Requirements validationdocs/requirements-validation.md
Scenario gapsdocs/scenario-gaps.md
Use-case coveragedocs/use-case-matrix.md
Session supervisor designdocs/workcell-session-supervisor-design.md
Managed workstation contractdocs/managed-workstation-contract.md
Enterprise evidence baselinedocs/enterprise-evidence-baseline.md
Enterprise rolloutdocs/enterprise-rollout.md
Host expansion readinessdocs/host-expansion-readiness.md
AWS EC2 SSM previewdocs/aws-ec2-ssm-preview.md
GCP VM previewdocs/gcp-vm-preview.md
Provenance and signingdocs/provenance.md
GitHub automationdocs/github-workflows.md
Artifact retention policydocs/retention-policy.md

Project docs

TopicFile
Contributor workflowCONTRIBUTING.md
SupportSUPPORT.md
Code of conductCODE_OF_CONDUCT.md
GovernanceGOVERNANCE.md
MaintainersMAINTAINERS.md
RoadmapROADMAP.md
ChangelogCHANGELOG.md
Security reportingSECURITY.md
Stability and exit-code contractdocs/stability-contract.md
Software engineering practicesdocs/software-engineering-practices.md
Standards watchlistdocs/standards-watchlist.md
Documentation languagedocs/documentation-language.md

Repository layout

  • runtime/: VM and container boundary implementation
  • policy/: shared contract layer and hosted-control policy
  • adapters/: provider-native baselines for Codex, Claude, Copilot, and Gemini, plus fail-closed Antigravity planning scaffolding
  • cmd/: host-side and runtime-side Go entrypoints (the workcell-* binaries)
  • internal/: shared Go packages backing the cmd/ binaries
  • scripts/: launcher, validation, release, audit, and bootstrap entrypoints
  • verify/: invariant-oriented verification material
  • man/: workcell.1 manpage
  • tests/: scenario manifests and fixtures
  • tools/: developer tooling (markdownlint, validator image)
  • docs/: user-facing design, quickstarts, install, and release docs
  • workflows/: implementation notes such as adapter porting guidance

License

Workcell is licensed under Apache-2.0. See LICENSE.

About

Bounded local runtime and policy boundary for coding agents

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

20 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,830 Commits

Folders and files

NameName
Last commit message
Last commit date

Workcell

CIDocsSecurity

Workcell runs coding agents in a bounded local runtime on Apple Silicon macOS. The strict runtime uses a hardened container in a dedicated Colima VM. Workcell supports Tier 1 adapters for Codex, Claude Code, GitHub Copilot CLI, and Gemini. Each adapter uses the native provider control plane. Provider configuration is not the security boundary. Workcell does not support --agent antigravity.

Use Workcell when a team needs local agents and an explicit runtime boundary. The safe path does not pass through the host home, keychain, provider state, or local sockets.

Why Workcell

  • keep the runtime boundary explicit: dedicated VM, hardened container, minimal mounts
  • keep provider adapters native: one shared boundary, thin provider-specific control-plane mapping
  • keep the normal publication workflow on the host: signed commits, signed-range verification, and GitHub publication stay out of Tier 1
  • keep publication authority explicit: credential injection can give a session publication authority
  • keep verification paths nonroot by default: runtime and validator images default to a named unprivileged workcell user, while repo-mounted validation lanes pass explicit caller UID/GID and isolated writable state, with a synthesized isolated home when the caller UID has no passwd entry in the image
  • keep lower-assurance paths visible: development, package mutation, transcripts, and breakglass are labeled instead of implied

How it compares

ApproachPrimary boundaryProvider-native control planeNormal publication pathLower-assurance paths called out
Host-native provider CLIhost user sessionyeshost user sessionrarely
Generic container wrappercontainer only, often mixed with host stateoften partialvariesoften unclear
Workcell strictdedicated Colima VM plus hardened containeryesseparate host workflowyes

Project status

  • v1.0.2 is the first published 1.0 release.
  • the published deprecation policy governs the frozen v1 public contract
  • Apple Silicon macOS hosts only today; Linux and Windows are not currently supported as launch hosts
  • local host-launched runtime first; cloud-facing paths today are the preview-only remote_vm/aws-ec2-ssm/compat and remote_vm/gcp-vm/compat broker plans, and their live smokes remain certification-only
  • CLI surfaces for Codex, Claude, Copilot, and upstream-served Gemini auth modes plus host-side detached session control and inspection commands
  • GitHub Copilot CLI uses explicit copilot_github_token staging through reviewed host-side inputs, converts it to a host-mounted token handoff outside mounted provider state, moves it through a transient runtime handoff file, and exports its value as COPILOT_GITHUB_TOKEN only to the managed Copilot child process, with isolated COPILOT_HOME and COPILOT_CACHE_HOME; host gh auth, Copilot provider state (~/.copilot, ~/.config/github-copilot, ~/.cache/github-copilot), keychains, and whole-home state are not safe-path inputs
  • Google Antigravity CLI is queued behind the same evidence bar and remains planned/fail-closed until Workcell ships adapter, auth, quickstart, deterministic evidence, and live certification together
  • GitHub-hosted CI verifies repo shape, reproducibility, release posture, and secretless runtime behavior
  • On Apple Silicon macos-26 and macos-15, hosted CI verifies bundle installation, launcher-link removal, and man-page-link removal. It also verifies Homebrew installation and formula removal.
  • the real macOS Colima boundary is still a local operator exercise because GitHub-hosted Linux runners cannot prove it
  • the canonical host support boundary lives in policy/host-support-matrix.tsv, and --doctor / --inspect emit matching host and support_matrix_* lines
  • Workcell does not yet ship a centralized enterprise policy, inventory, or analytics plane; team rollout today relies on distributing reviewed host-side files

The changelog identifies each breaking change. The roadmap identifies future work.

Community

  • use GitHub Discussions for usage questions, operator workflow notes, and open-ended design conversations
  • use GitHub issues for confirmed bugs and concrete feature requests
  • use SECURITY.md for security-sensitive reports

See SUPPORT.md, CONTRIBUTING.md, and CITATION.cff for the contributor and operator contract.

Choose your path

Pick the entry point that matches what you need. Each is a short labeled list of links; the full index is in the Docs map below.

5-minute path

Install Workcell, create the host-side auth policy, inspect the derived posture, then launch. ./scripts/install.sh below assumes you are in a verified or source tree; to install a tagged release instead, use the verified one-command path ./scripts/install-release.sh --version vX.Y.Z (see Install for the tag clone, signature checks, and the optional --attestation gate).

./scripts/install.sh
workcell auth init
workcell auth set \
--agent codex \
--credential codex_auth \
--source /Users/example/.config/workcell/codex-auth.json
workcell --agent codex --doctor --workspace /path/to/repo
workcell --agent codex --inspect --workspace /path/to/repo
workcell --agent codex --workspace /path/to/repo

For Copilot, use the provider-specific credential instead of the Codex auth file:

workcell auth set \
--agent copilot \
--credential copilot_github_token \
--source /Users/example/.config/workcell/copilot-github-token.txt
workcell --agent copilot --workspace /path/to/repo

Claude and Gemini use the same managed launch shape after their provider-specific auth is configured:

workcell --agent claude --workspace /path/to/repo
workcell --agent gemini --workspace /path/to/repo

See docs/getting-started.md for the release install path and provider-specific onboarding. For team rollout patterns on today's local-first product, see docs/enterprise-rollout.md. Use policy/host-support-matrix.tsv to interpret the host support boundary that --doctor and --inspect report.

Install

On Apple Silicon macOS, the recommended path is the one-command verified release install, which downloads a tagged release, verifies its cosign signature and digest fail-closed before any bundle code runs, and only then installs. install-release.sh is not a standalone release asset. Get it from the repository through TLS transport, not from the unverified bundle. Then authenticate the selected revision with the signed-tag check:

brew install cosign git gnupg # verifier tools must exist before verification runs (macOS ships neither gnupg nor, on a clean host, git)
git clone --branch vX.Y.Z --depth 1 https://github.com/omkhar/workcell.git
cd workcell
git tag -v vX.Y.Z # verify the tag signature before running the installer
./scripts/install-release.sh --version vX.Y.Z

Clone the tag (--branch vX.Y.Z), not the mutable default branch: the pre-trust installer runs before any release verification, so it must come from the signed, immutable release commit rather than whatever main currently holds. git tag -v authenticates that commit against the maintainer signing key before you execute the installer — import and confirm the key fingerprint from SECURITY.md first.

The verifier tools (cosign, and git/gnupg for the clone and tag check) must already be installed, because verification runs before the bundle installer that provides the other host packages (colima, docker, go); pass -- --no-install-deps for a launcher-only install. For an additional GitHub attestation check, append --attestation — that step needs gh installed and authenticated (brew install gh && gh auth login) and network access. To verify and install straight from the release page without a clone, use the manual cosign flow in docs/getting-started.md; if you already have a verified, unpacked release tree, run ./scripts/install.sh from inside it.

For the Homebrew formula asset, the source checkout path, and the full host requirements, see docs/install.md.

If you suspect an incident, preserve all available evidence before you run workcell --gc. See docs/incident-response.md. To reclaim stale runtime, cache, and temporary state without an uninstall, run workcell --gc. It removes aged transient session-audit.* scratch, not durable session records.

Run ./scripts/uninstall.sh --dry-run before you uninstall Workcell. Its output is the authoritative list. The uninstall command removes the launcher link and the managed state under ~/.local/state/workcell. It also removes Workcell-managed Colima profiles and caches. Workcell-managed profiles and caches use legacy workcell-* names or current wcl-* names. The command does not remove shared packages or unrelated profiles.

The uninstall command does not reach a custom WORKCELL_STATE_ROOT or XDG_STATE_HOME. Remove that custom state separately. After a Homebrew formula install, brew uninstall workcell removes only the formula. Also run ./scripts/uninstall.sh from a bundle or checkout to remove the runtime state. See docs/install-lifecycle.md.

Command reference

The supported commands at a glance; follow the links for the full behavior and options.

Docs map

Operator reference

TopicFile
Install and requirementsdocs/install.md
Onboarding and authdocs/onboarding-and-auth.md
Provider quickstartsdocs/provider-quickstarts.md
Mode mapdocs/mode-map.md
Safe-path expectationsdocs/safe-path-expectations.md
Release posturedocs/release-posture.md

Product and security docs

TopicFile
Getting starteddocs/getting-started.md
Support tiersdocs/support-tiers.md
Diagnostics and support matrixdocs/diagnostics-and-support-matrix.md
Security invariantsdocs/invariants.md
Threat modeldocs/threat-model.md
CI/CD threat modeldocs/ci-threat-model.md
OWASP agentic mappingdocs/owasp-agentic-mapping.md
Provider matrixdocs/provider-matrix.md
Provider bootstrap matrixdocs/provider-bootstrap-matrix.md
Adapter control planesdocs/adapter-control-planes.md
Injection policydocs/injection-policy.md
Validation coveragedocs/validation-scenarios.md
Requirements validationdocs/requirements-validation.md
Scenario gapsdocs/scenario-gaps.md
Use-case coveragedocs/use-case-matrix.md
Session supervisor designdocs/workcell-session-supervisor-design.md
Managed workstation contractdocs/managed-workstation-contract.md
Enterprise evidence baselinedocs/enterprise-evidence-baseline.md
Enterprise rolloutdocs/enterprise-rollout.md
Host expansion readinessdocs/host-expansion-readiness.md
AWS EC2 SSM previewdocs/aws-ec2-ssm-preview.md
GCP VM previewdocs/gcp-vm-preview.md
Provenance and signingdocs/provenance.md
GitHub automationdocs/github-workflows.md
Artifact retention policydocs/retention-policy.md

Project docs

TopicFile
Contributor workflowCONTRIBUTING.md
SupportSUPPORT.md
Code of conductCODE_OF_CONDUCT.md
GovernanceGOVERNANCE.md
MaintainersMAINTAINERS.md
RoadmapROADMAP.md
ChangelogCHANGELOG.md
Security reportingSECURITY.md
Stability and exit-code contractdocs/stability-contract.md
Software engineering practicesdocs/software-engineering-practices.md
Standards watchlistdocs/standards-watchlist.md
Documentation languagedocs/documentation-language.md

Repository layout

  • runtime/: VM and container boundary implementation
  • policy/: shared contract layer and hosted-control policy
  • adapters/: provider-native baselines for Codex, Claude, Copilot, and Gemini, plus fail-closed Antigravity planning scaffolding
  • cmd/: host-side and runtime-side Go entrypoints (the workcell-* binaries)
  • internal/: shared Go packages backing the cmd/ binaries
  • scripts/: launcher, validation, release, audit, and bootstrap entrypoints
  • verify/: invariant-oriented verification material
  • man/: workcell.1 manpage
  • tests/: scenario manifests and fixtures
  • tools/: developer tooling (markdownlint, validator image)
  • docs/: user-facing design, quickstarts, install, and release docs
  • workflows/: implementation notes such as adapter porting guidance

License

Workcell is licensed under Apache-2.0. See LICENSE.

About

Bounded local runtime and policy boundary for coding agents

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

20 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

1,830 Commits

Folders and files

NameName
Last commit message
Last commit date

Workcell

CIDocsSecurity

Workcell runs coding agents in a bounded local runtime on Apple Silicon macOS. The strict runtime uses a hardened container in a dedicated Colima VM. Workcell supports Tier 1 adapters for Codex, Claude Code, GitHub Copilot CLI, and Gemini. Each adapter uses the native provider control plane. Provider configuration is not the security boundary. Workcell does not support --agent antigravity.

Use Workcell when a team needs local agents and an explicit runtime boundary. The safe path does not pass through the host home, keychain, provider state, or local sockets.

Why Workcell

  • keep the runtime boundary explicit: dedicated VM, hardened container, minimal mounts
  • keep provider adapters native: one shared boundary, thin provider-specific control-plane mapping
  • keep the normal publication workflow on the host: signed commits, signed-range verification, and GitHub publication stay out of Tier 1
  • keep publication authority explicit: credential injection can give a session publication authority
  • keep verification paths nonroot by default: runtime and validator images default to a named unprivileged workcell user, while repo-mounted validation lanes pass explicit caller UID/GID and isolated writable state, with a synthesized isolated home when the caller UID has no passwd entry in the image
  • keep lower-assurance paths visible: development, package mutation, transcripts, and breakglass are labeled instead of implied

How it compares

ApproachPrimary boundaryProvider-native control planeNormal publication pathLower-assurance paths called out
Host-native provider CLIhost user sessionyeshost user sessionrarely
Generic container wrappercontainer only, often mixed with host stateoften partialvariesoften unclear
Workcell strictdedicated Colima VM plus hardened containeryesseparate host workflowyes

Project status

  • v1.0.2 is the first published 1.0 release.
  • the published deprecation policy governs the frozen v1 public contract
  • Apple Silicon macOS hosts only today; Linux and Windows are not currently supported as launch hosts
  • local host-launched runtime first; cloud-facing paths today are the preview-only remote_vm/aws-ec2-ssm/compat and remote_vm/gcp-vm/compat broker plans, and their live smokes remain certification-only
  • CLI surfaces for Codex, Claude, Copilot, and upstream-served Gemini auth modes plus host-side detached session control and inspection commands
  • GitHub Copilot CLI uses explicit copilot_github_token staging through reviewed host-side inputs, converts it to a host-mounted token handoff outside mounted provider state, moves it through a transient runtime handoff file, and exports its value as COPILOT_GITHUB_TOKEN only to the managed Copilot child process, with isolated COPILOT_HOME and COPILOT_CACHE_HOME; host gh auth, Copilot provider state (~/.copilot, ~/.config/github-copilot, ~/.cache/github-copilot), keychains, and whole-home state are not safe-path inputs
  • Google Antigravity CLI is queued behind the same evidence bar and remains planned/fail-closed until Workcell ships adapter, auth, quickstart, deterministic evidence, and live certification together
  • GitHub-hosted CI verifies repo shape, reproducibility, release posture, and secretless runtime behavior
  • On Apple Silicon macos-26 and macos-15, hosted CI verifies bundle installation, launcher-link removal, and man-page-link removal. It also verifies Homebrew installation and formula removal.
  • the real macOS Colima boundary is still a local operator exercise because GitHub-hosted Linux runners cannot prove it
  • the canonical host support boundary lives in policy/host-support-matrix.tsv, and --doctor / --inspect emit matching host and support_matrix_* lines
  • Workcell does not yet ship a centralized enterprise policy, inventory, or analytics plane; team rollout today relies on distributing reviewed host-side files

The changelog identifies each breaking change. The roadmap identifies future work.

Community

  • use GitHub Discussions for usage questions, operator workflow notes, and open-ended design conversations
  • use GitHub issues for confirmed bugs and concrete feature requests
  • use SECURITY.md for security-sensitive reports

See SUPPORT.md, CONTRIBUTING.md, and CITATION.cff for the contributor and operator contract.

Choose your path

Pick the entry point that matches what you need. Each is a short labeled list of links; the full index is in the Docs map below.

5-minute path

Install Workcell, create the host-side auth policy, inspect the derived posture, then launch. ./scripts/install.sh below assumes you are in a verified or source tree; to install a tagged release instead, use the verified one-command path ./scripts/install-release.sh --version vX.Y.Z (see Install for the tag clone, signature checks, and the optional --attestation gate).

./scripts/install.sh
workcell auth init
workcell auth set \
--agent codex \
--credential codex_auth \
--source /Users/example/.config/workcell/codex-auth.json
workcell --agent codex --doctor --workspace /path/to/repo
workcell --agent codex --inspect --workspace /path/to/repo
workcell --agent codex --workspace /path/to/repo

For Copilot, use the provider-specific credential instead of the Codex auth file:

workcell auth set \
--agent copilot \
--credential copilot_github_token \
--source /Users/example/.config/workcell/copilot-github-token.txt
workcell --agent copilot --workspace /path/to/repo

Claude and Gemini use the same managed launch shape after their provider-specific auth is configured:

workcell --agent claude --workspace /path/to/repo
workcell --agent gemini --workspace /path/to/repo

See docs/getting-started.md for the release install path and provider-specific onboarding. For team rollout patterns on today's local-first product, see docs/enterprise-rollout.md. Use policy/host-support-matrix.tsv to interpret the host support boundary that --doctor and --inspect report.

Install

On Apple Silicon macOS, the recommended path is the one-command verified release install, which downloads a tagged release, verifies its cosign signature and digest fail-closed before any bundle code runs, and only then installs. install-release.sh is not a standalone release asset. Get it from the repository through TLS transport, not from the unverified bundle. Then authenticate the selected revision with the signed-tag check:

brew install cosign git gnupg # verifier tools must exist before verification runs (macOS ships neither gnupg nor, on a clean host, git)
git clone --branch vX.Y.Z --depth 1 https://github.com/omkhar/workcell.git
cd workcell
git tag -v vX.Y.Z # verify the tag signature before running the installer
./scripts/install-release.sh --version vX.Y.Z

Clone the tag (--branch vX.Y.Z), not the mutable default branch: the pre-trust installer runs before any release verification, so it must come from the signed, immutable release commit rather than whatever main currently holds. git tag -v authenticates that commit against the maintainer signing key before you execute the installer — import and confirm the key fingerprint from SECURITY.md first.

The verifier tools (cosign, and git/gnupg for the clone and tag check) must already be installed, because verification runs before the bundle installer that provides the other host packages (colima, docker, go); pass -- --no-install-deps for a launcher-only install. For an additional GitHub attestation check, append --attestation — that step needs gh installed and authenticated (brew install gh && gh auth login) and network access. To verify and install straight from the release page without a clone, use the manual cosign flow in docs/getting-started.md; if you already have a verified, unpacked release tree, run ./scripts/install.sh from inside it.

For the Homebrew formula asset, the source checkout path, and the full host requirements, see docs/install.md.

If you suspect an incident, preserve all available evidence before you run workcell --gc. See docs/incident-response.md. To reclaim stale runtime, cache, and temporary state without an uninstall, run workcell --gc. It removes aged transient session-audit.* scratch, not durable session records.

Run ./scripts/uninstall.sh --dry-run before you uninstall Workcell. Its output is the authoritative list. The uninstall command removes the launcher link and the managed state under ~/.local/state/workcell. It also removes Workcell-managed Colima profiles and caches. Workcell-managed profiles and caches use legacy workcell-* names or current wcl-* names. The command does not remove shared packages or unrelated profiles.

The uninstall command does not reach a custom WORKCELL_STATE_ROOT or XDG_STATE_HOME. Remove that custom state separately. After a Homebrew formula install, brew uninstall workcell removes only the formula. Also run ./scripts/uninstall.sh from a bundle or checkout to remove the runtime state. See docs/install-lifecycle.md.

Command reference

The supported commands at a glance; follow the links for the full behavior and options.

Docs map

Operator reference

TopicFile
Install and requirementsdocs/install.md
Onboarding and authdocs/onboarding-and-auth.md
Provider quickstartsdocs/provider-quickstarts.md
Mode mapdocs/mode-map.md
Safe-path expectationsdocs/safe-path-expectations.md
Release posturedocs/release-posture.md

Product and security docs

TopicFile
Getting starteddocs/getting-started.md
Support tiersdocs/support-tiers.md
Diagnostics and support matrixdocs/diagnostics-and-support-matrix.md
Security invariantsdocs/invariants.md
Threat modeldocs/threat-model.md
CI/CD threat modeldocs/ci-threat-model.md
OWASP agentic mappingdocs/owasp-agentic-mapping.md
Provider matrixdocs/provider-matrix.md
Provider bootstrap matrixdocs/provider-bootstrap-matrix.md
Adapter control planesdocs/adapter-control-planes.md
Injection policydocs/injection-policy.md
Validation coveragedocs/validation-scenarios.md
Requirements validationdocs/requirements-validation.md
Scenario gapsdocs/scenario-gaps.md
Use-case coveragedocs/use-case-matrix.md
Session supervisor designdocs/workcell-session-supervisor-design.md
Managed workstation contractdocs/managed-workstation-contract.md
Enterprise evidence baselinedocs/enterprise-evidence-baseline.md
Enterprise rolloutdocs/enterprise-rollout.md
Host expansion readinessdocs/host-expansion-readiness.md
AWS EC2 SSM previewdocs/aws-ec2-ssm-preview.md
GCP VM previewdocs/gcp-vm-preview.md
Provenance and signingdocs/provenance.md
GitHub automationdocs/github-workflows.md
Artifact retention policydocs/retention-policy.md

Project docs

TopicFile
Contributor workflowCONTRIBUTING.md
SupportSUPPORT.md
Code of conductCODE_OF_CONDUCT.md
GovernanceGOVERNANCE.md
MaintainersMAINTAINERS.md
RoadmapROADMAP.md
ChangelogCHANGELOG.md
Security reportingSECURITY.md
Stability and exit-code contractdocs/stability-contract.md
Software engineering practicesdocs/software-engineering-practices.md
Standards watchlistdocs/standards-watchlist.md
Documentation languagedocs/documentation-language.md

Repository layout

  • runtime/: VM and container boundary implementation
  • policy/: shared contract layer and hosted-control policy
  • adapters/: provider-native baselines for Codex, Claude, Copilot, and Gemini, plus fail-closed Antigravity planning scaffolding
  • cmd/: host-side and runtime-side Go entrypoints (the workcell-* binaries)
  • internal/: shared Go packages backing the cmd/ binaries
  • scripts/: launcher, validation, release, audit, and bootstrap entrypoints
  • verify/: invariant-oriented verification material
  • man/: workcell.1 manpage
  • tests/: scenario manifests and fixtures
  • tools/: developer tooling (markdownlint, validator image)
  • docs/: user-facing design, quickstarts, install, and release docs
  • workflows/: implementation notes such as adapter porting guidance

License

Workcell is licensed under Apache-2.0. See LICENSE.

About

Bounded local runtime and policy boundary for coding agents

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

20 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages