Private state stays local
Runtime state, working context, memory stores, credentials, generated work, and personal configuration are treated as local or private data—not material for a public repository.
LOCAL-FIRST · TRUST-GATED
A living Agent can become deeply useful only when its reach is understandable. NativeAgent keeps private state local and places sensitive capability behind explicit trust.
THE TRUST MODEL
Local-first is the starting point. Permission levels, effect-time gates, signed mobile actions, domain verification, and durable receipts carry that principle into the places where the Agent can act.
Runtime state, working context, memory stores, credentials, generated work, and personal configuration are treated as local or private data—not material for a public repository.
Normal workspace access, Full Mac access, and operator-only Developer Mode remain separate. Even Developer Mode keeps protected-system hard floors in place.
The system keeps tool and skill bodies lazy instead of injecting every capability into every turn. That keeps context smaller and capability more intentional.
A transport response is not settlement. Durable receipts and domain readback keep important work reviewable and prevent a model from self-certifying success.
FROM THOUGHT TO ACTION
The Agent understands what is being requested.
The runtime decides what is allowed or gated.
Protected work waits for explicit permission.
The owning domain reads back reality before completion is trusted.
LOCAL DOES NOT MEAN ISOLATED
NativeAgent can use model providers, research, GitHub, messaging channels, and other connectors when they are configured. Those connections extend the Agent; they do not replace its Mac-native ownership.
Provider keys remain Mac-local. Exact connector availability varies, and NativeAgent remains a working single-operator system rather than a notarized public download.
Read the current project statusTRUST THE SOURCE