What Saeta is, and what it isn't
Saeta sits between your AI coding agent and your machine, and asks you before risky actions run. It is useful because it is honest about its limits.
What Saeta is
- A guardrail against agent mistakes: a hallucinated
rm -rf, a misread instruction, a command aimed at the wrong directory. - A safety net for your own slips, like approving the wrong thing in a hurry.
- One inbox for every agent's approval requests, on your desktop or your phone, so you can step away without turning permissions off.
What Saeta isn't
- A sandbox. An agent that can run shell commands has the same operating-system permissions as Saeta itself.
- A defence against a hostile agent. An agent that is deliberately trying to get around Saeta could, in principle, skip the hook, talk to Saeta directly, or rewrite its own configuration.
- A replacement for backups, version control, or reviewing what you merge.
How we raise the bar anyway
Saeta watches the agent configurations it installs and warns you if they change unexpectedly. It keeps its local connection and token readable only by your user account. If nobody answers a request, it falls back to the agent's own permission prompt instead of approving. That makes accidents much less likely to slip through. It does not make a determined attack impossible.
Why we spell this out
Security tools that overclaim put people at risk. If you need to contain an agent you don't trust, run it in a container or a virtual machine that can't reach anything you can't afford to lose.