Model-side malicious instruction.
A prompt injection or tampered instruction tries to leak secrets, damage files, or call a hostile endpoint. Picasso treats model requests as untrusted until the harness checks the action.
The risks Picasso is designed around.
A prompt injection or tampered instruction tries to leak secrets, damage files, or call a hostile endpoint. Picasso treats model requests as untrusted until the harness checks the action.
A third-party capability server attempts to exceed its declared permission profile. Picasso keeps server permissions explicit and records tool use in the session.
Generated or tested code behaves destructively when run through shell or test tools. Approval gates, shell policy, and workspace containment set the boundary.
A stale, staged, disabled, or break-glass-denied provider key should not become an invisible model route.
Picasso assumes that useful agents need tools, and tools need limits. The boundary is visible before the action, not explained after the fact.
File operations resolve absolute paths and deny escapes unless the user explicitly grants scope.
macOS, Linux, and Windows use native containment where available.
Tool and MCP network calls pass through allow and deny policy.
Writes and destructive actions surface blast radius before execution.
Provider key promotion, validation, rotation, disablement, and denial records are treated as security evidence.
Mode changes, approvals, denials, network violations, outside-workspace attempts, and secret detections are written to a tamper-evident HMAC chain. The log gives teams a local record of the decisions that mattered.
The sponsor runtime has no path into model output, tool results, plans, generated code, memory retrieval, model routing, or subagent dispatch. Sponsorship supports access without entering the work.
Picasso for Mac is almost here — a coding agent that looks the way serious tools should, and costs what creative freedom should: nothing. Leave your email and be first on the canvas.
Sponsors and labs — the early canvas is yours. Choose Sponsor or Lab above and we'll reach out before launch.