Security / identity is not isolation
BOT IDENTITY ≠ SECURITY BOUNDARY.
Real isolation uses accounts, credentials, permissions, scopes, sandboxes, approval gates, and infrastructure.
Treat as untrusted
- Third-party MCP servers
- Skills and repositories
- External workers
- Generated artifacts
- Shared prompts and packets
Minimum release boundary
- 1. Keep credentials out of role metadata, examples, logs, traces, and backups.
- 2. Use separate accounts and scopes for external workers.
- 3. Require explicit approval for consequential actions.
- 4. Redact before persistence, not just display.
- 5. Revoke and review after an incident.
Public packaging
The public repositories exclude harvest exports, account state, autonomy reports, browser/session data, cookies, tokens, keys, credentials, generated archives, and machine-specific paths.