๐๏ธ How it stays safe
Why an AI that reads outside email is risky, and the eight layers that keep a stranger's words from giving the agents orders.
๐๏ธ The email quarantine
How a stranger's email is read by a model with no tools, checked by code, and handed to the agent as a small form instead of raw text.
๐๏ธ The send guard
The last checkpoint. An agent send through it goes out only if it is to the owner, the owner said yes, or the agent is allowed that person.
๐๏ธ The memory guard
Text from an email or a form can never be written into the memory files that load into every future session.
๐๏ธ Tap to approve
The owner gets a link, taps Approve on a phone, and the box runs one exact command it wrote down ahead of time. Nothing else.
๐๏ธ Canary tripwires
Fake secrets planted in three private files. If one ever shows up in a commit or an outgoing message, it is refused and an alarm is written.
๐๏ธ Sender checks
How the box proves an email really came from the owner or a trusted partner, instead of trusting the name a sender typed.
๐๏ธ Server lockdown
The locks on the box itself. Even a hijacked agent program can't gain root, touch system folders, or run more than a short list of named commands.
๐๏ธ Secrets and logins
The AI reuses saved browser logins and never sees a password. API keys it must see, and they travel between machines only encrypted.
๐๏ธ Known limits
An honest list of what each safety layer misses, and what still stands behind it when it does.