Worca
Security

Autonomy, with limits.

Agents that run for an hour on their own need limits that don't depend on them behaving. Worca sets those limits outside the agent: on every spawn, around the whole process, and away from the keys.

worca — guardrails
Guardrails: named policy sets with Permissive, Normal, and Strict tiers
Guardrails

Pick the limits
per run.

Named policy sets, selected per run. Policies compile to hard permission denies on every agent spawn, and settings in the repo can't undo them.

Permissive

Let agents move fast in sandboxes and throwaway projects.

Normal

Protects credential files and blocks publication commands.

Strict

Adds environment scrub on spawn, network-egress and cloud-CLI denies, and home-dir credential protection.

⛨Your own policy setsStart from a tier, tune the rules, save it under a name, pick it per run.
⚇A team minimumA team policy can set the default guardrail set and the lowest tier anyone may pick.
≡Limits written downThe guardrails doc lists what a policy can and can't stop. Read it →
Container

Don't give agents
your whole laptop.

Worca and every agent it starts can run inside a disposable Linux container. One command sets it up. Your projects are mounted; your home folder is not. Signed images for Intel and Apple silicon.

terminal
# writes the compose files and starts the box
$ worca container up
# log Claude Code in, once
$ worca container login
$ worca container run -- --project ~/dev/api \
    --prompt "Add a /search endpoint"

The same UI, CLI, guardrails and plugins, on http://localhost:4317. Docker Desktop, Docker Engine or Podman.

Add-ons you can stack with --with

The boxno access to the host beyond your projectsalways
Network allowlistagents reach only the hosts you listegress
SSH agentlends the socket, not the keyssh
Team accessopens it to the team, behind a sign-inteams
Clone-inprojects are cloned inside, nothing mountedclonein
No keys

Agents never hold
a model key.

An agent that can read $ANTHROPIC_API_KEY can leak it, and so can a prompt injection in an issue or a web page. With the key service, keys live in a separate container. Each agent holds a pass that only works inside Worca, and only while its process lives.

0
model keys inside Worca
1
short-lived pass per agent
exit
the pass stops working when the agent exits
boot
Worca refuses to start if a key is in reach

On a shared Worca it also splits costs per person. Everyone pays with their own key →

Host guard

Agents can't kill
the host.

An implementer tidying up test servers once matched the production command line and killed the server running it. Now every spawn carries a hook that denies process-wide kills, the host's process id in its environment, and a preamble that names both.

What the hook says

… | xargs killpipe-fed killblocked
pkill -f server.mjsprocess-wideblocked
taskkill /IM node.exeby name, on Windowsblocked
kill 48213a literal id, not the hostallowed
  • ⌘
    macOS, Linux and WindowsThe same rules on every platform.
  • ≡
    Spawn diagnosticsA setting logs the binary, arguments and routing of each spawn, with no restart.
  • ↻
    One UI per machineTwo instances would fight over runs, so a second start points you at the running one.
Plugins

Nothing installs
without your say.

Plugins add task sources, agents, scripts, skills, workflows, models and chat channels. Each install shows what it adds first: which forms an agent can show and which file types they display, which secrets it needs, which setup commands run.

worca — plugins
Plugins view with installed plugins and marketplaces
  • ✓
    An explicit consent stepWhat is installed, what it can show you, what it runs.
  • ±
    Updates show their commitsA commit-level preview before you accept an update.
  • ⚇
    Required by the team, still your clickA team policy can require a plugin; it's offered in a checklist, never installed silently.
Your repo

Your checkout
stays clean.

A worktree per runEvery run works on its own git worktree and branch. Your working copy is never touched.
State outside the repoOne SQLite database in your home directory, keyed by repo identity, stable across worktrees.
Memory never committedAgent memory stays out of git and out of every commit a run makes.
Free and open source · MIT

Ship work you
didn't babysit.

One npm install on macOS, Linux or Windows. Or a container, or a shared server for the team.