[{"data":1,"prerenderedAt":366},["ShallowReactive",2],{"navigation_docs":3,"-guide-safety":168,"-guide-safety-surround":361},[4,146],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":36},"Guide","i-lucide-book-open","\u002Fguide","1.guide",[10,14,37,55,59,63,67,71,75,79,83,87,109,134,138,142],{"title":11,"path":12,"stem":13},"What is Agent Zero?","\u002Fguide\u002Fintroduction","1.guide\u002F1.introduction",{"title":15,"icon":16,"path":17,"stem":18,"children":19,"page":36},"API","i-lucide-plug","\u002Fguide\u002Fapi","1.guide\u002F10.api",[20,24,28,32],{"title":21,"path":22,"stem":23},"API overview","\u002Fguide\u002Fapi\u002Foverview","1.guide\u002F10.api\u002F1.overview",{"title":25,"path":26,"stem":27},"Define endpoints","\u002Fguide\u002Fapi\u002Fdefine-endpoints","1.guide\u002F10.api\u002F2.define-endpoints",{"title":29,"path":30,"stem":31},"Use the API from a client","\u002Fguide\u002Fapi\u002Fuse-from-client","1.guide\u002F10.api\u002F3.use-from-client",{"title":33,"path":34,"stem":35},"Protect endpoints","\u002Fguide\u002Fapi\u002Fprotect-endpoints","1.guide\u002F10.api\u002F4.protect-endpoints",false,{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":36},"Authentication","i-lucide-lock","\u002Fguide\u002Fauthentication","1.guide\u002F11.authentication",[43,47,51],{"title":44,"path":45,"stem":46},"Authentication overview","\u002Fguide\u002Fauthentication\u002Foverview","1.guide\u002F11.authentication\u002F1.overview",{"title":48,"path":49,"stem":50},"GitHub OAuth","\u002Fguide\u002Fauthentication\u002Foauth","1.guide\u002F11.authentication\u002F2.oauth",{"title":52,"path":53,"stem":54},"Permissions","\u002Fguide\u002Fauthentication\u002Fpermissions","1.guide\u002F11.authentication\u002F3.permissions",{"title":56,"path":57,"stem":58},"Organizations","\u002Fguide\u002Forganizations","1.guide\u002F12.organizations",{"title":60,"path":61,"stem":62},"Frontend","\u002Fguide\u002Ffrontend","1.guide\u002F13.frontend",{"title":64,"path":65,"stem":66},"Mails","\u002Fguide\u002Fmails","1.guide\u002F14.mails",{"title":68,"path":69,"stem":70},"Internationalization","\u002Fguide\u002Finternationalization","1.guide\u002F15.internationalization",{"title":72,"path":73,"stem":74},"Deployment","\u002Fguide\u002Fdeployment","1.guide\u002F16.deployment",{"title":76,"path":77,"stem":78},"Tech stack","\u002Fguide\u002Ftech-stack","1.guide\u002F2.tech-stack",{"title":80,"path":81,"stem":82},"Installation","\u002Fguide\u002Finstallation","1.guide\u002F3.installation",{"title":84,"path":85,"stem":86},"Environment variables","\u002Fguide\u002Fenvironment-variables","1.guide\u002F4.environment-variables",{"title":88,"icon":89,"path":90,"stem":91,"children":92,"page":36},"Codebase","i-lucide-folder-tree","\u002Fguide\u002Fcodebase","1.guide\u002F5.codebase",[93,97,101,105],{"title":94,"path":95,"stem":96},"Codebase structure","\u002Fguide\u002Fcodebase\u002Fstructure","1.guide\u002F5.codebase\u002F1.structure",{"title":98,"path":99,"stem":100},"Dependencies","\u002Fguide\u002Fcodebase\u002Fdependencies","1.guide\u002F5.codebase\u002F2.dependencies",{"title":102,"path":103,"stem":104},"Formatting and linting","\u002Fguide\u002Fcodebase\u002Fformatting-linting","1.guide\u002F5.codebase\u002F3.formatting-linting",{"title":106,"path":107,"stem":108},"Agent Skills","\u002Fguide\u002Fcodebase\u002Fagent-skills","1.guide\u002F5.codebase\u002F4.agent-skills",{"title":110,"icon":111,"path":112,"stem":113,"children":114,"page":36},"Architecture","i-lucide-layers","\u002Fguide\u002Farchitecture","1.guide\u002F6.architecture",[115,118,122,126,130],{"title":110,"path":116,"stem":117},"\u002Fguide\u002Farchitecture\u002Foverview","1.guide\u002F6.architecture\u002F1.overview",{"title":119,"path":120,"stem":121},"State machine","\u002Fguide\u002Farchitecture\u002Fstate-machine","1.guide\u002F6.architecture\u002F2.state-machine",{"title":123,"path":124,"stem":125},"Execution boundary","\u002Fguide\u002Farchitecture\u002Fexecution-boundary","1.guide\u002F6.architecture\u002F3.execution-boundary",{"title":127,"path":128,"stem":129},"Issue-to-PR workflow","\u002Fguide\u002Farchitecture\u002Fissue-to-pr","1.guide\u002F6.architecture\u002F4.issue-to-pr",{"title":131,"path":132,"stem":133},"Adding a capability","\u002Fguide\u002Farchitecture\u002Fadding-a-capability","1.guide\u002F6.architecture\u002F5.adding-a-capability",{"title":135,"path":136,"stem":137},"Repository policy","\u002Fguide\u002Fconfiguration","1.guide\u002F7.configuration",{"title":139,"path":140,"stem":141},"Safety model","\u002Fguide\u002Fsafety","1.guide\u002F8.safety",{"title":143,"path":144,"stem":145},"Database","\u002Fguide\u002Fdatabase","1.guide\u002F9.database",{"title":147,"icon":148,"path":149,"stem":150,"children":151,"page":36},"Reference","i-lucide-book-marked","\u002Freference","2.reference",[152,156,160,164],{"title":153,"path":154,"stem":155},"CLI","\u002Freference\u002Fcli","2.reference\u002F1.cli",{"title":157,"path":158,"stem":159},"Model providers","\u002Freference\u002Fmodel-providers","2.reference\u002F2.model-providers",{"title":161,"path":162,"stem":163},"Source-control providers","\u002Freference\u002Fsource-control-providers","2.reference\u002F3.source-control-providers",{"title":165,"path":166,"stem":167},"Sandbox providers","\u002Freference\u002Fsandbox-providers","2.reference\u002F4.sandbox-providers",{"id":169,"title":139,"body":170,"description":176,"extension":355,"links":356,"meta":357,"navigation":358,"path":140,"seo":359,"stem":141,"__hash__":360},"docs\u002F1.guide\u002F8.safety.md",{"type":171,"value":172,"toc":344},"minimark",[173,177,182,189,195,199,207,250,253,257,260,264,289,293,315,319,330,334],[174,175,176],"p",{},"Agent Zero is built so that the safe path is the default path and every escalation is explicit, auditable, and reversible.",[178,179,181],"h2",{"id":180},"observe-by-default","Observe by default",[174,183,184,188],{},[185,186,187],"code",{},"observe"," is the default mode and never writes to a target repository. A fresh deployment, an unconfigured repository, or a webhook from an unknown source can only ever produce a report.",[174,190,191,192,194],{},"Regardless of provider, a webhook can never escalate a run: parsed events produce ",[185,193,187],{},"-mode input unless the deployment's own policy chooses otherwise, and an unverifiable delivery is rejected before its payload is parsed.",[178,196,198],{"id":197},"the-authorization-chain-for-writes","The authorization chain for writes",[174,200,201,202,206],{},"Automatic changes require ",[203,204,205],"strong",{},"all"," of the following:",[208,209,210,221,227,233,240,243],"ol",{},[211,212,213,216,217,220],"li",{},[185,214,215],{},"mode: fix"," or ",[185,218,219],{},"mode: autonomous"," in repository policy;",[211,222,223,226],{},[185,224,225],{},"autofix.enabled: true",";",[211,228,229,230,226],{},"model confidence at or above ",[185,231,232],{},"autofix.minConfidence",[211,234,235,236,239],{},"a change-risk class listed in ",[185,237,238],{},"autofix.allowedChangeRisks"," — high-impact changes always require human approval and cannot be allow-listed;",[211,241,242],{},"repository-native checks that pass after the change;",[211,244,245,246,249],{},"by default for proactive, issue, or autonomous work: an isolated runner (",[185,247,248],{},"autofix.requireIsolated",").",[174,251,252],{},"Each refusal in this chain is a distinct reportable outcome rather than a silent downgrade, and a failed verification is never presented as success.",[178,254,256],{"id":255},"untrusted-input","Untrusted input",[174,258,259],{},"Review feedback, model output, issue text, and remote content are all untrusted input — data for the runtime to validate, never instructions. Validation decides the verdict from repository evidence, not from anyone's assertion.",[178,261,263],{"id":262},"one-execution-boundary","One execution boundary",[174,265,266,267,270,271,274,275,274,278,280,281,284,285,288],{},"Only ",[185,268,269],{},"packages\u002Frunner"," may invoke shell commands or mutate a checkout. Commands run without a shell, so operators such as ",[185,272,273],{},"&&",", ",[185,276,277],{},"|",[185,279,226],{},", and ",[185,282,283],{},"$()"," are rejected. Working directories, arguments, timeouts, and output limits are validated at the boundary. See ",[286,287,123],"a",{"href":124},".",[178,290,292],{"id":291},"secrets","Secrets",[294,295,296,299,309,312],"ul",{},[211,297,298],{},"Credentials are read only from fixed, documented environment variables — never from repository configuration.",[211,300,301,302,305,306,288],{},"Endpoint URLs cannot be named in ",[185,303,304],{},".agent-zero.yml","; a custom endpoint can only come from the operator-owned ",[185,307,308],{},"AGENT_ZERO_MODEL_BASE_URL",[211,310,311],{},"Task records are redacted before they are written and never contain review input or checkout paths.",[211,313,314],{},"Provider credentials never enter a sandbox request, lease snapshot, agent state, or log.",[178,316,318],{"id":317},"production-isolation","Production isolation",[174,320,321,322,325,326,329],{},"The included ",[185,323,324],{},"LocalRunner"," is intended for trusted local development. Production deployments must place execution inside Docker, a microVM, or another ephemeral sandbox with CPU, memory, filesystem, and network policies — set ",[185,327,328],{},"runner.isolation: container"," in repository policy.",[178,331,333],{"id":332},"reporting-vulnerabilities","Reporting vulnerabilities",[174,335,336,337,343],{},"Report vulnerabilities privately as described in ",[286,338,342],{"href":339,"rel":340},"https:\u002F\u002Fgithub.com\u002Fwolfstar-project\u002Fagent-zero\u002Fblob\u002Fmain\u002FSECURITY.md",[341],"nofollow","SECURITY.md",". Do not open a public issue.",{"title":345,"searchDepth":346,"depth":346,"links":347},"",2,[348,349,350,351,352,353,354],{"id":180,"depth":346,"text":181},{"id":197,"depth":346,"text":198},{"id":255,"depth":346,"text":256},{"id":262,"depth":346,"text":263},{"id":291,"depth":346,"text":292},{"id":317,"depth":346,"text":318},{"id":332,"depth":346,"text":333},"md",null,{},true,{"title":139,"description":176},"ui90Cm4f3B-zzzvg5IRX-1dOZGnQrAnobfmPboLvAUY",[362,364],{"title":135,"path":136,"stem":137,"description":363,"children":-1},"Agent Zero reads its per-repository policy from .agent-zero.yml at the repository root. Create one with:",{"title":143,"path":144,"stem":145,"description":365,"children":-1},"Agent Zero's runtime is deliberately persistence-free. The repository contains exactly one database — Postgres, used by the dashboard's authentication session store — and one package that owns it.",1787482152792]