Signed and hash-pinned packages
The catalogue signature is checked and the installed binary hash is revalidated whenever the app launches.
Verify what is running, scan what is entering, constrain what the app may touch, and retain evidence of the decision—before an agent tool becomes an invisible authority channel.
Authority is derived from a verified package and an explicit local grant—not from the model request alone.
Give us a representative action. We will break down its content, package, grant, execution, and audit boundaries against Pilot’s current security surfaces.
An agent tool can hold credentials, read files, reach remote services, or launch a process. A convenient configuration is not the same thing as a security boundary. Pilot’s app runtime makes the package, binary, grants, and execution state inspectable, while AEGIS adds a local screening layer for prompt injection and related content risks.
The catalogue signature is checked and the installed binary hash is revalidated whenever the app launches.
Filesystem, network, process, signing, and audit access can be declared and reviewed per app.
AEGIS can scan commands, files, tool results, memory, and skills for injection, impersonation, and obfuscation patterns.
Review the publisher, methods, required grants, protection mode, and integrity state.
The local policy stays narrower than the app’s possible capability surface.
Pilot checks the pinned artifact before supervising the app process.
App calls and policy-relevant actions can be written to the local audit surface.