Selo wraps any AI coding agent in a contained worktree, audits what it actually changed, and produces an Ed25519-signed receipt for every outcome. Not "the agent said it's done" — a verifiable record.
# one-time install (or: go install github.com/C1-run/selo/cmd/selo@latest) curl -fsSL https://raw.githubusercontent.com/C1-run/selo/main/install.sh | bash # make signatures attributable across runs selo keys generate # initialize a workspace and run a task through the pipeline selo init selo run "fix the login bug" # read the verdict — always from the receipt, never from the agent selo receipt list selo receipt show <id> --format github
| Capability | Status |
|---|---|
| Post-run audit | Forbidden file edits, claims, secrets, patch/round limits, test integrity — violations reject the task with a signed receipt. |
| permission_allowlist | Enforced as a post-run scope check (globs). Does not sandbox the agent process. |
| Signed receipts | Ed25519 over canonical JSON; selo keys generate makes signatures attributable across runs. |
| selo verify | Anyone can re-check a receipt's hash and signature — third-party verification is a one-liner. |
| Containment | Git worktree only. docker/local are refused, not silently degraded. |
| Real-time interception | Does not exist. The audit is post-execution only. |
Post the receipt card into a GitHub Actions job summary — no token, no marketplace. The card always shows the integrity state, so a tampered receipt can never look clean.
Running an MCP client? selo mcp serve exposes the real
checks — audit diffs and scan paths without a reimplementation.
## Selo receipt `c1f-…` **Verdict: `FAILED_SAFETY`** — integrity: hash ✅ signature ✅ **Safety findings (1):** - forbidden file modified: src/secret.rs
Selo is maintained by C1-run (team@c1.run). Every claim on this page is checked against the code in the repository — read the What works table for the full list, including what does not exist yet.