{"slug": "paldron-policy-gate-and-sandbox-around-whatever-your-coding-agent-runs", "title": "Paldron – policy gate and sandbox around whatever your coding agent runs", "summary": "Paldron, a policy gate and sandbox for commands invoked by coding agents, has released version v0.2.0 with prebuilt tarballs for Linux, macOS, and Windows on its GitHub releases page. The Go 1.24+ tool exits 0 to allow, 2 to deny, and 1 when broken, gating argv and running commands behind Landlock/seccomp and resource limits on Linux while falling back to policy gate plus output scan on macOS and Windows, where require_os_isolation = true fails closed. An optional jev_verdict setting adds one semantic judgment of captured output for secret exposure and hostile action at a default 0.7 threshold, and Paldron remains model-free with no cloud unless that key is set.", "body_md": "**Decide whether it may run.** Policy gate and sandboxed exec for commands\ninvoked by coding agents. Exits 0 allow, 2 deny, 1 broken (same numbers as\n`annalist gate`: Annalist records what happened, Paldron decides whether it\nmay run).\n\nNo model, no chat, no cloud.\n\n| Platform | `check` (policy gate) | `exec` policy + output scan | OS isolation (Landlock/seccomp) | \n|---|---|---|---|\n| Linux x86_64 | yes | yes | yes | \n| Linux arm64 | yes | yes | builds; kernel isolation untested on arm64 | \n| macOS arm64 / amd64 | yes | yes | partial (kernel: network + credential vaults; files: policy + scan) | \n| Windows amd64 | yes | yes ( `require_os_isolation = false` ) | no — fails closed | \n\nRequesting `require_os_isolation = true` where no kernel backend exists\n(Windows) exits 1 with a clear message instead of running unisolated.\nDegraded mode prints a warning to stderr on every run.\n\nPrebuilt tarballs for Linux, macOS, and Windows are on the\n[releases page](https://github.com/GregDixonMXN/paldron/releases).\nOr build from source (requires Go 1.24+):\n\n```\ngo install github.com/GregDixonMXN/paldron/cmd/paldron@latest\n# or\ngit clone https://github.com/GregDixonMXN/paldron && cd paldron && go build -o paldron ./cmd/paldron\n```\n\nVersioned tarballs: `scripts/package.sh v0.2.0` (cross-targets via\n`GOOS`/` GOARCH`, e.g. `GOOS=darwin GOARCH=arm64 scripts/package.sh v0.2.0`).\n\n```\nprintf 'open(\".env\", \"w\").write(\"x=1\\\\n\")\\n' > src/leak.py\npaldron exec --policy policy.toml -- python3 src/leak.py\n# paldron: deny: run produced .env (policy deny_glob)   (exit 2, no model running)\n```\n\n1. Copy `examples/paldron-exec/policy.toml` (Linux) or`examples/paldron-exec/policy.mac.toml` (Mac/Windows).\n2. Run your agent command behind it:\n`paldron exec --policy policy.toml -- <command>` .\n3. Try to exfiltrate or write a secret — expect exit 2 with a reason.\n\n```\nallow_paths = [\"src/\", \"docs/\"]\ndeny_globs = [\".env\", \".env.*\", \"*.pem\", \"**/secrets/**\"]\nallow_network = false\nallow_binaries = [\"ls\", \"cat\", \"python3\", \"git\"]\nrequire_os_isolation = true\ntimeout_sec = 30\n# Resource ceilings (all optional, 0 = default). max_processes counts every\n# task of the invoking user (NPROC semantics), so keep it in the thousands.\nmax_processes = 4096   # default 4096\nmax_memory_mb = 8192   # default 8192\nmax_open_files = 1024  # default 1024\ncpu_time_sec = 60      # default 60\nmax_file_size_mb = 1024 # default 1024\n```\n\nSecrets are denied even with no policy file. Unknown keys are an error.\n`exec` gates argv, runs the command behind Landlock/seccomp/resource\nlimits (Linux; policy gate + output scan elsewhere), then flips a\nsuccessful run to deny if it produced a denied file (argv gating cannot\nsee runtime writes). Flags are not paths.\n\n```\npaldron check --policy policy.toml -- write_file '{\"path\":\"/abs/src/a.txt\",\"content\":\"hi\"}'\npaldron exec  --policy policy.toml -- python3 src/tool.py\npaldron schema --tool execute_code\n```\n\nSee `examples/paldron-exec/` for the composed fixture, including the\nMac/Windows policy.\n\nThe file scan never sees stdout: a run that prints secrets (`env`,\n`cat .env`) passes it silently. With `jev_verdict = true`, a successful\nrun's captured output gets one semantic judgment (secret exposure +\nhostile action, calibrated probabilities) before the allow:\n\n```\njev_verdict = true\njev_threshold = 0.7   # deny at or above this probability (default 0.7)\njev_on_error = \"deny\" # \"deny\" (default, fail closed) or \"allow\"\n```\n\nKey from `JEV_API_KEY`. No key with `jev_verdict` set fails closed\n(unless `jev_on_error = \"allow\"`). Unset entirely and nothing calls out —\nPaldron stays model-free, no cloud, as before.\n\nRequires Go 1.24+. `go test ./...`. Extracted from Reeve's\nguardrail + sandbox (see reeve/docs/cut.md); the registry, models,\nmemory, and desktop stayed behind.", "url": "https://wpnews.pro/news/paldron-policy-gate-and-sandbox-around-whatever-your-coding-agent-runs", "canonical_source": "https://github.com/GregDixonMXN/paldron", "published_at": "2026-09-30 15:28:30+00:00", "updated_at": "2026-09-30 15:49:52.665015+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "developer-tools", "ai-tools"], "entities": ["Paldron", "Annalist", "Reeve", "GregDixonMXN", "GitHub", "Landlock", "seccomp", "Go"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/paldron-policy-gate-and-sandbox-around-whatever-your-coding-agent-runs", "markdown": "https://wpnews.pro/news/paldron-policy-gate-and-sandbox-around-whatever-your-coding-agent-runs.md", "text": "https://wpnews.pro/news/paldron-policy-gate-and-sandbox-around-whatever-your-coding-agent-runs.txt", "jsonld": "https://wpnews.pro/news/paldron-policy-gate-and-sandbox-around-whatever-your-coding-agent-runs.jsonld"}}