Malicious model instruction.
The model can ask for unsafe actions. The harness gates them.
Permissions, sandboxing, network policy, and audit logs.
Permissions, sandboxing, network policy, and audit logs.
The model can ask for unsafe actions. The harness gates them.
External servers run with declared permissions.
Shell, file, and network access are contained by mode.
Default scope stays inside the workspace.
Seatbelt, Landlock, namespaces, or Windows job restrictions.
Allowlists and denylists for risky commands.
Host allow and deny rules.
Writes outside policy require approval.
Potential secrets are detected before exposure.
| Mode | Behavior |
|---|---|
| safe. | Read and approved writes. |
| auto. | Safe classes can auto-accept. |
| yolo. | Unrestricted trusted-workspace mode for short-lived local work only. |
| paranoid. | No terminal sponsor surfaces and stricter gates. |
The local audit log records mode changes, approvals, denials, network policy events, secret detections, and outside-workspace attempts. It is designed as a chain so tampering is visible.
The admin control plane keeps sensitive production changes behind evidence, approvals, rollback references, and audit records. Routing, budget, setup, provider-vault, account, and usage surfaces show no-evidence states instead of pretending a gate passed.
Health gates, metrics, timelines, rollout selectors, and failed-gate reasons can block activation.
Alias health, staged rotation, emergency disable state, validation history, and break-glass denial evidence stay visible.
Managed usage, margin detail, settlement status, worker state, and redacted export artifacts are operator-visible.
Sponsor content never enters model output.
Tool results stay untouched.
Generated files stay clean.
Sponsors do not steer models, tools, or subagents.
Sponsor partners do not receive prompts, outputs, or code.
A dedicated security contact is published the day Picasso opens. Reports should include the affected version, reproduction steps, impact, and any relevant logs. Picasso confirms receipt, investigates the boundary involved, and publishes security notes with scope, fixed issues, and residual risk when a public disclosure is appropriate.
Picasso for Mac is almost here — a coding agent that looks the way serious tools should, and costs what creative freedom should: nothing. Leave your email and be first on the canvas.
Sponsors and labs — the early canvas is yours. Choose Sponsor or Lab above and we'll reach out before launch.