IMPLEMENTED
Repository operations, GitHub pull requests and diagnostics, Coolify deployment, Brain memory, bounded results, authenticated console and outbound Edge workcells.
MCP DEVBOX
CHATGPT WORKING ON REAL INFRASTRUCTURE WITHOUT RECEIVING A FREE SHELL.
solution ........ narrow tools and verifiable operations [BOUNDED]
autonomy ........ read-only / review / bounded autonomy [CONFIGURED]
proof ............ Pixelgrama, built and deployed on CubePath [PUBLIC]
this page ........ public presentation with no operational authority [ENFORCED]
00 · WHAT IT SOLVES
A general shell gives the model more authority than most tasks require.
MCP Devbox lets an agent read, change, test, publish and deploy projects through narrow tools, immutable policy, denied secrets and verifiable operations.
The owner chooses between read-only access, explicit review or autonomy within preconfigured limits.
PRODUCT STATUS
Repository operations, GitHub pull requests and diagnostics, Coolify deployment, Brain memory, bounded results, authenticated console and outbound Edge workcells.
Broader execution profiles and advanced local workcells remain evidence-driven rather than assumed universal.
Multi-tenant operation and universal isolation are not claimed. Any future expansion must preserve the same authority boundary.
02 · READ-ONLY GUIDED DEMO
This story is generated from Pixelgrama's public, versioned manifest. It does not query GitHub during page load and grants no authority over MCP Devbox.
DEMO BOUNDARY
Public, unauthenticated and read-only. It cannot invoke tools, open the console, approve plans, request grants, read credentials or access repositories.
Loading the embedded public manifest...
Awaiting evidence...
The canonical summary is shown verbatim from the public manifest.
Includes
Excludes
Purposes and SHAs come from the manifest. Each PR's public Files changed view keeps the file-level detail without duplicating it here.
—
Direct and plan-protected operation classes are documented publicly; plan IDs, approvals and audit remain private.
Documented direct operations
Plan-protected operations
In ask, a reviewable effect waits for approval. In allow, an authorized operation may continue without that pause. In both cases, the plan remains exact, temporary, revalidated and single-use. Pixelgrama's exact historical mode is not publicly proven.
Awaiting comparison...
Earlier PR SHAs are historical evidence. The observed commit above is the production state verified on the stated date.
03 · POLICY EXPLORER
Choose a request. This is a local simulation of documented policy outcomes. It sends no request to MCP Devbox and grants no authority.
SELECT A REQUEST
policy> awaiting local input
Every verdict names the invariant that produces it.
04 · REQUEST PATH
05 · HOST & ADMISSION
The control plane runs on a 2 vCPU, 3.805 GiB KVM guest. The dated 2026-07-22 baseline measured idle and a real no-cache deployment. CPU, not memory, was the demonstrated binding resource.
| MEASURE | RESULT | INTERPRETATION |
|---|---|---|
| idle CPU p95 | 41.10% | control-plane baseline |
| intensive build CPU p95 | 93.20% | serialized heavy work |
| host memory peak | 2.33 GiB | no OOM observed |
| CPU steal | negligible | guest workload contention |
Both preflights returned 0. All six calibration runs completed with exit status 0 and zero OOM. The deterministic selector chose 65%; 50% was rejected by duration regression.
06 · EVIDENCE
FAIL five High container findings and one reachable Go vulnerability blocked closure.
FIXED affected packages were upgraded or removed; the final image gate proved zero High/Critical findings.
CLOSED CodeQL path and cookie findings were remediated at source with adversarial regression tests.
SEALED PR #57 made the catalog discoverable and passed 16 exact-head checks.
SEALED PR #58 normalized documentary whitespace without weakening literal contracts; 16 checks passed.
ACCEPTED P16 target-VPS calibration selected 65% after two preflights and six successful runs.
A threshold is not edited to obtain green. A failure is diagnosed, a bounded change is made, and the full exact-head gate set runs again.
07 · VULNERABILITY LEDGER
GO-2026-5856 was reachable through repository call paths.
Three High findings existed in the final runtime image.
Affected sigstore and picomatch copies remained after the first attempted upgrade.
Remote repository input previously participated in validation-runner paths.
Dynamic cookie security could not be proven on every path.
08 · LIVE RUNTIME IDENTITY
This panel reads the same safe public identity exposed by /version. No credential is sent and no private state is requested.
Loading public runtime identity.
Independent checks: liveness JSON identity authenticated operator console.
09 · HONEST LIMITS
Any agent. Any stack. Explicit guardrails. Auditable delivery.