Cue runs natural-language coding goals through Codex CLI inside approved folders only β capability-zero AppContainer isolation, a fixed execution envelope, and no credentials written to the UI or ledger. Built for people who want a local coding agent with hard boundaries. Not related to Maestro Cue.
Follow-up from the maker: the design bet behind Cue is the messy middle between YOLO-everything and an endless approval loop.
Approve an execution envelope (approved worktree + scope) once β capability-zero AppContainer workers run workspace actions there β and that envelope does not silently expand after approval. Credentials arenβt written to the UI or ledger.
Honest limits: Windows 11 + Codex CLI only; UAC/elevated friction doesnβt magically disappear; AppContainer is a real OS boundary, not a proof of βno bypass ever.β Critical issues welcome on GitHub.
Follow-up from the maker: the design bet behind Cue is the messy middle between YOLO-everything and an endless approval loop.
Approve an execution envelope (approved worktree + scope) once β capability-zero AppContainer workers run workspace actions there β and that envelope does not silently expand after approval. Credentials arenβt written to the UI or ledger.
Honest limits: Windows 11 + Codex CLI only; UAC/elevated friction doesnβt magically disappear; AppContainer is a real OS boundary, not a proof of βno bypass ever.β Critical issues welcome on GitHub.
Repo: https://github.com/zenovis2-crea...
Demo: https://github.com/zenovis2-crea...