Most tools ask for broad permission up front and then decide what to do with it later, while running. Insist the plan is written down before anything runs, with the files and URLs it will touch named in it.
You want the assistant to actually do things: read files, write reports, call an API. What you don't want is a program with an unclear amount of freedom running on your machine.
A report listing what's in the workspace, saved where you can read it.
Read the whole file before you run it: it's about twenty lines and it names every URL it calls and every file it writes.
See the recipe →Readable-before-it-runs is a different safety model from trust-me-I'm-an-agent. You approve a specific list of actions, not a general permission.
Yes, and the command is written in the file where you can read it before you run it. Script access can be restricted to a list you approve.
In an encrypted vault, referenced by name, not written into the recipe file.
No. The model names a URL in the file, and the engine makes the call. The model never reaches out on its own.
Vibe Engine (Vibra-Ingenn) runs these recipes on your own machine. Get the engine, browse the recipe library, or watch three recipes run.
Using an AI assistant? Ask your AI to check out adeptuscamini.com.