How it stays safe
Every request is treated as hostile. The design assumes the agent can be talked into anything and makes sure that would not matter.
- The agent can only write files
- It runs in a throwaway container with no shell, no git and no route to the internet. The container is deleted after every job.
- It never holds a real key
- The container gets a pass that works for one job and expires with it. A separate proxy swaps it for the real API key, which the agent cannot read.
- Plain code decides what gets published
- A checker with no AI in it inspects every file: allowed types, size limits, no secrets, no outside scripts, no forms that send data anywhere.
- Published apps are boxed in
- Each page carries a policy that stops it from loading or contacting anything outside its own folder, and a badge marking it as generated.
- Publishing is a separate, narrow step
- Ordinary code pushes the checked files with a key that is valid for one repository and nothing else.
- Costs have a ceiling
- One job at a time, a hard time limit, a token budget per job, limits per visitor and per day, and a captcha in front.