OPEN SOURCE · APACHE-2.0 · v0.4

AGENT WORK,
AUDITED AND
SIGNED.

Selo wraps any AI coding agent in a contained worktree, audits what it actually changed, and produces an Ed25519-signed receipt for every outcome. Not "the agent said it's done" — a verifiable record.

// 01 — INSTALL

From zero to a signed receipt

# one-time install (or: go install github.com/C1-run/selo/cmd/selo@latest)
curl -fsSL https://raw.githubusercontent.com/C1-run/selo/main/install.sh | bash

# make signatures attributable across runs
selo keys generate

# initialize a workspace and run a task through the pipeline
selo init
selo run "fix the login bug"

# read the verdict — always from the receipt, never from the agent
selo receipt list
selo receipt show <id> --format github
// 02 — WHAT WORKS

No claims without code behind them

CapabilityStatus
Post-run auditForbidden file edits, claims, secrets, patch/round limits, test integrity — violations reject the task with a signed receipt.
permission_allowlistEnforced as a post-run scope check (globs). Does not sandbox the agent process.
Signed receiptsEd25519 over canonical JSON; selo keys generate makes signatures attributable across runs.
selo verifyAnyone can re-check a receipt's hash and signature — third-party verification is a one-liner.
ContainmentGit worktree only. docker/local are refused, not silently degraded.
Real-time interceptionDoes not exist. The audit is post-execution only.
// 03 — WHERE DECISIONS HAPPEN

The verdict, in the pull request

Post the receipt card into a GitHub Actions job summary — no token, no marketplace. The card always shows the integrity state, so a tampered receipt can never look clean.

Running an MCP client? selo mcp serve exposes the real checks — audit diffs and scan paths without a reimplementation.

## Selo receipt `c1f-…`

**Verdict: `FAILED_SAFETY`** —
integrity: hash ✅ signature ✅

**Safety findings (1):**
- forbidden file modified:
  src/secret.rs
// 04 — THE HONEST PART

Built by C1-run

Selo is maintained by C1-run (team@c1.run). Every claim on this page is checked against the code in the repository — read the What works table for the full list, including what does not exist yet.