Paldron – policy gate and sandbox around whatever your coding agent runs Paldron, a policy gate and sandbox for commands invoked by coding agents, has released version v0.2.0 with prebuilt tarballs for Linux, macOS, and Windows on its GitHub releases page. The Go 1.24+ tool exits 0 to allow, 2 to deny, and 1 when broken, gating argv and running commands behind Landlock/seccomp and resource limits on Linux while falling back to policy gate plus output scan on macOS and Windows, where require_os_isolation = true fails closed. An optional jev_verdict setting adds one semantic judgment of captured output for secret exposure and hostile action at a default 0.7 threshold, and Paldron remains model-free with no cloud unless that key is set. Decide whether it may run. Policy gate and sandboxed exec for commands invoked by coding agents. Exits 0 allow, 2 deny, 1 broken same numbers as annalist gate : Annalist records what happened, Paldron decides whether it may run . No model, no chat, no cloud. | Platform | check policy gate | exec policy + output scan | OS isolation Landlock/seccomp | |---|---|---|---| | Linux x86 64 | yes | yes | yes | | Linux arm64 | yes | yes | builds; kernel isolation untested on arm64 | | macOS arm64 / amd64 | yes | yes | partial kernel: network + credential vaults; files: policy + scan | | Windows amd64 | yes | yes require os isolation = false | no — fails closed | Requesting require os isolation = true where no kernel backend exists Windows exits 1 with a clear message instead of running unisolated. Degraded mode prints a warning to stderr on every run. Prebuilt tarballs for Linux, macOS, and Windows are on the releases page https://github.com/GregDixonMXN/paldron/releases . Or build from source requires Go 1.24+ : go install github.com/GregDixonMXN/paldron/cmd/paldron@latest or git clone https://github.com/GregDixonMXN/paldron && cd paldron && go build -o paldron ./cmd/paldron Versioned tarballs: scripts/package.sh v0.2.0 cross-targets via GOOS / GOARCH , e.g. GOOS=darwin GOARCH=arm64 scripts/package.sh v0.2.0 . printf 'open ".env", "w" .write "x=1\\n" \n' src/leak.py paldron exec --policy policy.toml -- python3 src/leak.py paldron: deny: run produced .env policy deny glob exit 2, no model running 1. Copy examples/paldron-exec/policy.toml Linux or examples/paldron-exec/policy.mac.toml Mac/Windows . 2. Run your agent command behind it: paldron exec --policy policy.toml --