ai.blog.sateda.dev
Harness design, MCP governance, workflow methodology, and a running survey of what agent execution environments actually look like from the inside.
← all of blog.sateda.devA growing set of agent-environment probes — per-vendor audits plus the running cross-environment comparison. It has its own hub.
Every probed environment (chat, Cowork, Kimi, Grok, Devin ×2, AI Studio) and the comparison's full revision history, 3-way through 7-way, in one place.
The latest: seven environments, five vendors, two proven by nonce — and one fabricated submission excluded.
Full root and nothing gets out: all 41 capabilities, nested virt, and a wall for egress. Execution proven by nonce.
A desktop, not a build box: X11/VNC/KDE, the richest toolchain surveyed, open egress. Proven by nonce.
Five programs and an agent on a floppy: 8 cores, 32 GiB, and no compiler — a Rust agent driving Git bash.
Google AI Studio audited: a Cloud Run app-preview host scored as if it were a code-execution sandbox — a category error.
Where it started: chat, Cowork, and Kimi — the containment-vs-capability axis and egress-as-intent thesis.
Harness mechanisms, MCP governance, workflow methodology, and model-routing teardowns.
Verdict-gated speech: letting a language model answer immediately and audibly repair itself mid-utterance.
The consolidated methodology: the philosophy, the settled six-phase spec, proposed amendments, and open threads.
A governance-lane MCP gateway whose code mostly keeps its word — except one unsafe default in the encrypted vault.
Rigorous routing research whose statistical guarantee can't transfer to the open-ended product sold on its credibility.