ContextOS assumes that language models (LLMs) are highly capable but fundamentally untrusted actors. They can hallucinate destructive commands, output vulnerable code, or inadvertently execute path traversal attacks. The execution environment must fail-closed.
-
Host Filesystem Boundary:
- The LLM cannot write arbitrary files to the host.
- All filesystem writes must flow through
JournaledTransaction, which strictly enforcessafe-path.jsconstraints. - UNC paths, network drives, and path traversals (
../) are explicitly blocked.
-
Execution Boundary (Sandbox):
- LLMs cannot execute shell commands directly on the host operating system unless explicitly permitted by user override in
host-unsafemode. - Code execution defaults to OCI-compliant containers (Docker/Podman).
- Containers are launched with:
--read-onlyroot filesystem.--cap-drop=ALLand--security-opt=no-new-privileges.--network=noneby default.- Ephemeral, isolated
tmpfsmounts.
- LLMs cannot execute shell commands directly on the host operating system unless explicitly permitted by user override in
-
Concurrency Boundary:
- Multiple agents or processes attempting concurrent modifications are serialized by
ProjectMutationLock. ProjectMutationLockguarantees single-writer semantics and prevents corrupted intermediate states using UUID tokens.
- Multiple agents or processes attempting concurrent modifications are serialized by
- Supply Chain: Plugin execution requires the supply chain to be cryptographically verifiable. Floating or unpinned plugins are rejected by default.
- Host-Unsafe Override: If a user explicitly allows
host-unsafemode, the sandbox protections are bypassed. In this state,AutoMergeis disabled to ensure a human remains in the loop.
ContextOS operates as a deterministic static compiler and pre-commit governance engine:
- Enforces safe paths and atomic journaled writes on the host filesystem.
- Scans the Git staged index (
contextos scan --staged) for leaked credentials, blocked files (.env), and unfinished lazy stubs prior to commit. - Runs verification gates in CI (
contextos gate).
During active model inference and tool execution (in-flight), language models can encounter indirect prompt injection (e.g. malicious GitHub issues, poisoned dependency READMEs, or untrusted MCP results) and attempt external data egress or destructive shell commands before any Git commit occurs.
To achieve complete zero-trust defense across the entire AI engineering lifecycle, ContextOS is designed to complement local runtime action firewalls, such as Stroq:
- Static Rules & Context (ContextOS): Defines and compiles engineering policies, role boundaries, and architectural guidelines into native IDE configurations.
- In-Flight Action Firewall (e.g. Stroq): Intercepts tool calls in real time, monitors taint from untrusted reads, and deterministically denies outbound secret egress (
deny-secret-egress) or self-tampering of governance files (deny-self-tamper). - Commit Governance (ContextOS): Verifies the Git staged index and prevents dirty commits.
- CI/CD Quality Gate (ContextOS): Verifies adapter parity and rule synchronization.