Workspace guide

A workshop, not remote control of your computer.

Read, edit, propose and review code here. Run it with your own installed tools only after a local trust decision.

1. Read and build

Opening a project never installs packages, starts an agent or runs code. Add files and propose a change. A stale version never overwrites a newer one.

2. Invite deliberately

A project URL is not a login. Invitations require the exact intended signed-in account. The owner chooses Viewer, Reviewer, Editor or Maintainer. Agent credentials are separate, scoped and revocable.

3. Run locally

The optional connector only syncs source by default. No website request can start PowerShell. Approve the local source digest and a locally defined command profile before running. Local processes are not sandboxed: use a disposable isolated environment for untrusted code.

Local connector

Download the script and inspect it. Python 3.11 or later is required. Install the connector outside shared folders. Run python -I /path/signum_workspace.py --help for commands. Use the terminal interactively; do not paste an access key into a project file or a URL.

Download connector source
python -I C:/Tools/signum_workspace.py --folder C:/Projects/MyLab init --site https://neuralsymboliclanguage.com --project PROJECT_ID
python -I C:/Tools/signum_workspace.py --folder C:/Projects/MyLab status
python -I C:/Tools/signum_workspace.py --folder C:/Projects/MyLab fetch
python -I C:/Tools/signum_workspace.py --folder C:/Projects/MyLab apply
python -I C:/Tools/signum_workspace.py --folder C:/Projects/MyLab push
python -I C:/Tools/signum_workspace.py --folder C:/Projects/MyLab watch

Fetch stages a snapshot outside your project; it does not overwrite your work. Apply explicitly after review. Watch sends private proposed snapshots only, never merges or runs them. Only explicitly selected tracked source is uploaded. Common credential paths and recognizable keys are blocked, but detection is not exhaustive: inspect every proposed upload. Dependencies and console output are not synchronized automatically.

Trust is specific, not a green safety badge

Review warnings identify possible credentials, hidden Unicode and execution configuration. They are not malware detection. Run approval belongs to your computer and the exact selected profile, not to a project owner, an AI message or a shared settings file. Changed source invalidates prior local run approval.

Private knowledge stays separate

Project files, comments, receipts, preferences and private history are not ingested into Hive. Hive is private platform infrastructure for approved agents and operators. Published documentation is available separately.

Optional agent connection

The Project MCP adapter uses Node 22 or later and connects an MCP-capable client to one project. It offers five source, proposal and comment tools, with no execution or merge tool. Configure the project URL and credential in the client’s private environment, not in shared source. Real external-provider compatibility must be tested separately.

Current limits

Projects store up to 64 text files and 96 KiB total source per snapshot. This is not Git hosting, a real-time multi-cursor editor, an antivirus product, or an isolated cloud runner. Run commands may access your operating-system account; a warning cannot contain malicious code.

Project protocol · Privacy notice