Write Velaris, audit what it can touch, and run it under an effect budget.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Run code an AI wrote without handing it everything you can reach.
Each function declares what it may touch. You grant the run one folder, one host or a number of calls, and the runtime refuses anything else the moment it's tried.
Not a security boundary by itself: an interpreter in the program's own process enforces the budget. From 8.4 the operating system is asked to hold the same budget under it - fully on Linux, partly on macOS and on Windows - and each run says which it got (THREAT_MODEL.md, docs/confinement.md).
Playground · Documentation · Guides · Reference · Paper
Formerly Velaris - why the name changed
Who it is for. The person about to run a program a model wrote - on a laptop, in CI, behind an MCP server - who wants what it can touch bounded by what they said, not by what the program says about itself. It bounds programs written in Sabline, not a Python or shell script the same model might write instead.
See it refuse, in one command - no arguments, no network, under a
minute. It writes the kind of script an agent writes (read ./.env, post it
to a webhook), runs it with no budget given, and shows the refusal and the
run's receipt; then the same task inside a budget:
It writes what it runs and reads nothing of yours; --keep leaves the files,
and sabline receipt show renders either receipt as a page.
This project was called Velaris until 8.6.0. The name belongs to an
unrelated company in the same market (velaris.io), so it was given up
rather than contested. Everything else is unchanged, and nothing written
against the old name stops working in 8.x: the velaris command, import velaris, the VELARIS_* environment variables, a committed
velaris.capabilities, and a velaris.audit/1 or velaris.receipt/1
document are all still read, each saying once that the name has changed.
docs/renamed.md lists every published address and where
it now points; STABILITY.md says what goes in 9.0.
That program cannot open a socket, read a file, call Python, or ask the clock. Not "shouldn't" — the runtime refuses, and a refusal cannot be caught and carried past. You do not have to read the code, understand it, or trust the compiler's analysis of it.
Since 5.0 that is what a run with no --allow gets: io, the
console. It used to be all seven effects, which meant the answer to
"what may this program do?" was "everything" until an operator said
otherwise. Widen it by naming what the program needs
(--allow io,fs:read:./data); --allow all grants every effect and
writes one line to stderr saying so.
--allow io,ffi:math,json grants Python for those modules only; a call
that reaches any other module — named, or reached through an attribute of
a granted one — is refused (E311). A granted module can still do whatever
that module itself can do: ffi:os is the operating system. Since 3.0
the same grammar
narrows every coarse effect: fs:read:./data, fs:write:./out,
net:api.example.com:443, net:*.example.com, and @100 for at most
that many operations in a run; env is its own effect, so an
io-only program cannot read the environment. timeout and
max_memory_mb are available through the library and every door, and
on a door the operator's limits are ceilings a caller cannot raise.
It is still not a security boundary - but the
caveats every review raised, the ffi cliff, unbounded execution, and
fs and net with no path or host list, are now precise permissions
rather than holes. It is a real guard for the situation everyone is
now in — running a program someone, or something, else wrote.
That ensures is not a comment or a runtime assert. The Z3 theorem
prover verifies it for every possible input before execution — and
refutes it with an exact counterexample when it lies.
A commerce platform lets each customer write their own discount rule. This one has the shape most of them have: a percentage off once the basket passes a threshold, a flat amount off as well, and a cap on the two together.
The two ensures are what the platform needs to know about a rule it
did not write: a discount is never a surcharge, and what is left after
it is never negative. Both are settled for every basket and every rule
the types allow, before the program runs.
examples/discount.vel is the whole program —
proven, and it runs under --allow io.
examples/discount_bad.vel is the same
rule with the last if deleted. The cap still holds the discount to a
fixed ceiling; nothing holds it to what the basket is worth:
The amounts are in paise: a basket worth nothing, a flat discount of two paise held down to a cap of one, and one paisa handed back anyway. The program does not run.
A sandbox answers a different question. It can stop this rule reading a file or opening a socket; it cannot tell you whether the arithmetic holds.
Effects say a program printed something. They do not say whether what
it printed was the secret. Secret of T (6.0, 7.0) is the other half: the
compiler tracks the value, and refuses any program that hands it to
anything that emits.
examples/secret.vel reads an API key, builds
the request that would carry it, and prints a summary of that request.
examples/secret_bad.vel is the same
program with one more line:
Nothing ran, nothing was logged, and no reviewer had to notice the
line. A list of secrets, a map of them, or a record with one secret
field carries it too, so the whole structure is refused at a sink — a
Request record holding the key cannot be printed either.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/velaris)<a href="https://allmcps.com/mcp/velaris"><img src="https://allmcps.com/api/badge/velaris?style=directory" alt="Velaris on AllMCPs" /></a>