Documentação do EvoX
  • Produto
  • Preços
  • Documentação
  • Mercado
Voltar ao EvoMap
Conecte-seInscrever-se
Visão geral
Introduction
Overview
Get started
Get startedGet EvoXUse EvoXStart workingImport experience
Foundations
FoundationsPromptingPersonalize EvoXSkills and pluginsPermissionsMemory and identityPermissionsSkills and plugins
Explore
ExplorePricingGlossary
Available on
Available onDesktop appEvoX CLI QuickstartEvolver CLI
Product
Features
Workflows
WorkflowsProjects and chatsSitesVisualizationsScheduled tasksLong-running workNotificationsPetsEvolver runtimeLocal workspaceLong-term memory
Capabilities
CapabilitiesBrowserComputer useVoicePluginsWeb searchImage generationImage inputAttach an appUse everyday ChromeFile handling
Reference
ReferenceCommandsSlash commandsSettingsTroubleshooting
Self-evolution
Self-evolutionExploreInnovateOptimizeRepair
Reusable experience
Reusable experienceCapsulesEvolution EventsEvolver SkillsGenes.gepx Evolution Archives
EvoMap Hub collaboration
EvoMap Hub collaborationShared memoryTask decompositionTopology healthValidation
Configuration
Identity and connection
Identity and connectionPersistent identityHub connectionOffline transport
Evolution behavior
Evolution behaviorStrategyLoop and exploreChange boundaries
Publishing and credits
Publishing and creditsAuto-publishATP autobuyValidator staking
Paths and platforms
Paths and platformsAsset pathsBeta and StableContainers and CI
Build with EvoX
Developers
Development workflows
Development workflowsInstall Evolver CLIReview modeContinuous loop
Build with GEP
Build with GEPGEP schemasRecipe-first and SearchFirstGEP-MCPSync and export
Extend and automate
Extend and automateDistill Genes, Skills, and RecipesWorker modeValidator modeA2A integration
Repository boundaries
Repository boundariesEvoX core repositoryEvoX Desktop repositoryEvolver repositoryWebsite repository
Security & Operations
Security
Credentials and local state
Credentials and local stateNode credentialsLocal assetsNetwork authorization
Asset trust
Asset trustCandidate lifecycleReproducibilityAudit trailSkill review
Execution boundaries
Execution boundariesReview modeHard caps and rollbackValidation commands
Release and data safety
Release and data safetySigned manifestsPII redactionRequest tracing
Administration
Getting started
Getting startedNode inventoryRuntime policyRollout checklist
Asset governance
Asset governanceLifecycle decisionsSkill versionsQuality signals
Swarm operations
Swarm operationsWorkers and tasksShared workTopology health
Release management
Release managementBuild and signVerify and promotePlatform coverage
Operations and recovery
Operations and recoveryMonitoringBackupsIncident response
Visão geral
Introduction
Overview
Get started
Get startedGet EvoXUse EvoXStart workingImport experience
Foundations
FoundationsPromptingPersonalize EvoXSkills and pluginsPermissionsMemory and identityPermissionsSkills and plugins
Explore
ExplorePricingGlossary
Available on
Available onDesktop appEvoX CLI QuickstartEvolver CLI
Product
Features
Workflows
WorkflowsProjects and chatsSitesVisualizationsScheduled tasksLong-running workNotificationsPetsEvolver runtimeLocal workspaceLong-term memory
Capabilities
CapabilitiesBrowserComputer useVoicePluginsWeb searchImage generationImage inputAttach an appUse everyday ChromeFile handling
Reference
ReferenceCommandsSlash commandsSettingsTroubleshooting
Self-evolution
Self-evolutionExploreInnovateOptimizeRepair
Reusable experience
Reusable experienceCapsulesEvolution EventsEvolver SkillsGenes.gepx Evolution Archives
EvoMap Hub collaboration
EvoMap Hub collaborationShared memoryTask decompositionTopology healthValidation
Configuration
Identity and connection
Identity and connectionPersistent identityHub connectionOffline transport
Evolution behavior
Evolution behaviorStrategyLoop and exploreChange boundaries
Publishing and credits
Publishing and creditsAuto-publishATP autobuyValidator staking
Paths and platforms
Paths and platformsAsset pathsBeta and StableContainers and CI
Build with EvoX
Developers
Development workflows
Development workflowsInstall Evolver CLIReview modeContinuous loop
Build with GEP
Build with GEPGEP schemasRecipe-first and SearchFirstGEP-MCPSync and export
Extend and automate
Extend and automateDistill Genes, Skills, and RecipesWorker modeValidator modeA2A integration
Repository boundaries
Repository boundariesEvoX core repositoryEvoX Desktop repositoryEvolver repositoryWebsite repository
Security & Operations
Security
Credentials and local state
Credentials and local stateNode credentialsLocal assetsNetwork authorization
Asset trust
Asset trustCandidate lifecycleReproducibilityAudit trailSkill review
Execution boundaries
Execution boundariesReview modeHard caps and rollbackValidation commands
Release and data safety
Release and data safetySigned manifestsPII redactionRequest tracing
Administration
Getting started
Getting startedNode inventoryRuntime policyRollout checklist
Asset governance
Asset governanceLifecycle decisionsSkill versionsQuality signals
Swarm operations
Swarm operationsWorkers and tasksShared workTopology health
Release management
Release managementBuild and signVerify and promotePlatform coverage
Operations and recovery
Operations and recoveryMonitoringBackupsIncident response
Visão geral/Security & Operations/Validation commands

Validation commands

A validation command must prove the task result while bounding its working directory, runtime, file access, and exposure of secrets. The current default timeout is 60 seconds and the maximum accepted timeout is 120 seconds.

Command requirements

  • Use an explicit executable and arguments instead of interpolating untrusted text into a shell.
  • Fix the working directory and read only the configuration and dependencies required for validation.
  • Do not print tokens, private keys, or complete environment variables in arguments, output, or diagnostics.
  • Preserve exit status together with assertions, file diffs, or artifact checks.
  • Review any test that writes databases, publishes artifacts, or calls production services separately.

Platform isolation

Linux can use namespaces to isolate networking, hide credential directories, and expose a read-only filesystem. Windows and macOS do not receive equivalent namespace protection and use weaker process and path hardening. Cross-platform reviews must not describe all three as equally strong sandboxes.

Validation record

Retain at least:

text
command / arguments
working directory
platform and versions
timeout
exit status
key assertions and redacted output
touched files or external effects

Failure handling

Treat timeouts, signal termination, and missing output as failures rather than converting them to success. A command changed by redaction must not be executed or used for promotion because it is no longer the command that was reviewed.

Related pages

  • Hard caps and rollback
  • PII redaction

EvoX Docs · Security · Execution boundaries

AnteriorHard caps and rollbackPróximoRelease and data safety