[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:ephemora-cell":3},"\u003Ch1>Ephemora Cell\u003C\u002Fh1>\n\u003Ch3>Secure execution for untrusted AI-generated code.\u003C\u002Fh3>\n\u003Cp>Run AI-generated code, MCP tools and plugins inside an enforced capability boundary — explicit resource limits, auditable execution records.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>8\u002F8 attack vectors blocked · 424 tests · sub-millisecond warm execution\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Built for \u003Cstrong>AI agents, MCP tools, plugins, code interpreters, and other untrusted workloads.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Fast, capability-based WASM execution: CPU, memory, time, I\u002FO and filesystem budgets enforced per execution, with sign-ready execution records (RFC 8785 JCS canonicalization + ES256 \u003Ccode>sign()\u003C\u002Fcode>\u002F\u003Ccode>verify()\u003C\u002Fcode> primitives).\u003C\u002Fp>\n\u003Cp align=\"center\">\n  \u003Ca href=\"https:\u002F\u002Fpypi.org\u002Fproject\u002Fephemora-cell\u002F\" rel=\"nofollow ugc noopener\">\n    \u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fpypi\u002Fv\u002Fephemora-cell\" alt=\"PyPI\" \u002F>\n  \u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fwww.python.org\u002Fdownloads\u002F\" rel=\"nofollow ugc noopener\">\n    \u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fpython-3.10%2B-blue\" alt=\"Python 3.10+\" \u002F>\n  \u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fopensource.org\u002Flicenses\u002FApache-2.0\" rel=\"nofollow ugc noopener\">\n    \u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Flicense-Apache--2.0-green\" alt=\"License\" \u002F>\n  \u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FMichaelS1011\u002Fephemora-cell\" rel=\"nofollow ugc noopener\">\n    \u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fstatus-stable-brightgreen\" alt=\"Status\" \u002F>\n  \u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FMichaelS1011\u002Fephemora-cell\u002Fstargazers\" rel=\"nofollow ugc noopener\">\n    \u003Cimg src=\"https:\u002F\u002Fimg.shields.io\u002Fgithub\u002Fstars\u002FMichaelS1011\u002Fephemora-cell\" alt=\"GitHub stars\" \u002F>\n  \u003C\u002Fa>\n\u003C\u002Fp>\u003Cp align=\"center\">\n  \u003Cpicture>\n    \u003Csource media=\"(prefers-color-scheme: dark)\" srcset=\"assets\u002Fhero-dark.svg\">\u003C\u002Fsource>\n    \u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002FMichaelS1011\u002Fephemora-cell\u002FHEAD\u002Fassets\u002Fhero-light.svg\" alt=\"AI Agent → Ephemora Cell enforcement stack → bounded result\" \u002F>\n  \u003C\u002Fpicture>\n\u003C\u002Fp>\u003Ch2>The problem\u003C\u002Fh2>\n\u003Cp>AI agents increasingly need to write and execute code, call tools, and run plugins. The question that decides whether that is safe:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How do you let an agent execute untrusted code without giving that code access to your host, your credentials, your network, or unlimited compute?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-text\">AI Agent ──▶ Tool \u002F MCP ──▶ Ephemora Cell ──▶ WASM ──▶ bounded result\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cstrong>Ephemora Cell\u003C\u002Fstrong> is a small, capability-based WASM execution runtime for exactly that job: an execution primitive — not an agent framework — that sits underneath your existing agent stack, MCP server, plugin system, or application.\u003C\u002Fp>\n\u003Ch2>Every execution leaves evidence\u003C\u002Fh2>\n\u003Cp>Every tool call answers three questions at once — attached to the result as \u003Ccode>_meta.execution\u003C\u002Fcode>, canonicalized (RFC 8785 JCS) and signable:\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>\u003C\u002Fth>\n\u003Cth>Answer\u003C\u002Fth>\n\u003Cth>Example fields\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>\u003Cstrong>RESULT\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>what came back\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>status\u003C\u002Fcode>, \u003Ccode>stdout\u003C\u002Fcode>, \u003Ccode>exit_code\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>COST\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>what it cost\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>fuel_consumed\u003C\u002Fcode>, \u003Ccode>elapsed_ms\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>POLICY\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>under which rules it ran\u003C\u002Ftd>\n\u003Ctd>memory limit, preopens, network policy, \u003Ccode>wasmtime_version\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\n\u003Cp>\"Verified. Not claimed.\" is a data field, not a slogan. Runnable demo: \u003Ccode>python examples\u002Fsigned_record_demo.py\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch2>Quick Start\u003C\u002Fh2>\n\u003Cp>Three commands: install Cell, run something untrusted, read its audited receipt.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1 — Install\u003C\u002Fstrong> (use a virtualenv; on Ubuntu ≥ 23.04 \u002F Fedora a bare \u003Ccode>pip install\u003C\u002Fcode>\nis refused by PEP 668. Windows: use Git Bash or WSL, and \u003Ccode>python\u003C\u002Fcode> instead of \u003Ccode>python3\u003C\u002Fcode>):\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">python3 -m venv .venv &amp;&amp; source .venv\u002Fbin\u002Factivate\npython -m pip install ephemora-cell\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cstrong>2 — Run something untrusted\u003C\u002Fstrong> (the repo ships examples, or bring any \u003Ccode>.wasm\u003C\u002Fcode>):\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">git clone https:\u002F\u002Fgithub.com\u002FMichaelS1011\u002Fephemora-cell.git &amp;&amp; cd ephemora-cell\nephemora-cell run examples\u002Fhello.wasm --isolated\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cem>(adds OS-level process isolation around the run, a few ms — recommended for code you didn't build)\u003C\u002Fem>\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-text\">Hello from Ephemora Cell!\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cstrong>3 — Read the audited receipt\u003C\u002Fstrong> — same run, machine-readable. Here a hostile module\n(\u003Ccode>examples\u002Ffuel_bomb.wasm\u003C\u002Fcode>) is given a 100-unit fuel budget and stopped, exactly as\nbudgeted:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ephemora-cell run examples\u002Ffuel_bomb.wasm --fuel 100 --isolated --json\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cpre>\u003Ccode class=\"language-json\">{\n  \"status\": \"fuel_exhausted\",\n  \"exit_code\": 0,\n  \"fuel_consumed\": 100,\n  \"fuel_budget\": 100,\n  \"stdout_bytes\": 0\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Same from Python — every result carries status, cost and captured output:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-python\">\n\u003C\u002Fcode>\u003C\u002Fpre>\n",1789816648740]