In-process filesystem confinement and command-policy guardrails for autonomous agents.
Agents that can touch arbitrary files or run arbitrary commands are a supply-chain risk.
Filesystem allow/deny, command-policy engine, audit log, and configurable policy.
Agent boundaries become enforceable, not just documented.
Policy → filesystem interceptor + command interceptor → audit.
packages/engineering/ packages/local-core/ src/entry.mjs
{ path, op }{ allowed, reason }import { guard } from './src/entry.mjs'Node.js 20+ · v1.0.0
Bundled suite
Proprietary non-exclusive
GENESIS Direct: Active · private · automatic · USDC on Base