Code and tools you do not trust yet
A cloned repository can carry instructions meant for your agent. A new MCP server can do more than its name says. Memnox treats both as new until you say otherwise.
A repository you did not write
memnox run --untrusted -- claudeInside that run, on macOS and Linux:
- writes stay inside the repository and temp folders
- your home folder's key files, like
~/.sshand~/.aws, cannot be read - every network request goes through Memnox and asks
When you memnox run in a repository nobody here has worked in, Memnox
suggests --untrusted for you.
Repositories an agent clones
A repository an agent clones itself starts on probation for seven days. The
agent can still read and run it, but its .env files are refused and anything
outward or destructive asks.
memnox repo list # what is on probation
memnox repo trust ./project # end it once you have lookedA new MCP server
Look before you trust it:
memnox scan --mcp github # what this server can do, tool by tool
memnox scan --tools # every tool on every serverA server Memnox just wrapped, and an agent it just found, also start on probation for seven days: reads go through, writes and outward actions ask.
memnox status # what is on probation, and until when
memnox mcp trust github # end a server's probation
memnox agents trust cursor # end an agent's probationAfter probation, only your rules decide.
Keep secrets out of reach everywhere
Setup already denies reading ~/.ssh and .env files in every repository. To
add your own, for example a folder of certificates:
[[policies]]
name = "no-certs"
[policies.match]
actions = [ "filesystem.read" ]
targets = [ "certs/**" ]
[policies.decision]
effect = "deny"
reason = "Private certificates are never needed to read or run this code."
[policies.decision.alternative]
action = "filesystem.read"
resource = "certs/README.md"
note = "Read certs/README.md for what each one is for."