A coding agent on Windows.
It runs the tests. No WSL.
Any conversation can code. The code playbook brings a shell that runs inside a sandbox Windows itself enforces, a repo map and the dev loop. It fixes the thing, runs the tests, and leaves the commit for you to read.

VectorBrain’s real interface, running on example data. The project and its code are invented.
A sandbox Windows enforces.
Every command runs under a write-restricted token inside a job object. Those are kernel objects, not a path check in the app. A command can write to the project and the toolchain caches, and everything it started dies when the app closes.
No WSL2, no Docker, no virtual machine. It does not confine what a command reads and it leaves the network open, and the app’s settings say both in the sandbox’s own words.
build the sitemap for the launch page

It reads a map before it starts.
Tree-sitter parses the project into a ranked list of files and the definition lines other files depend on, up to 12,000 characters, in front of every run once the code playbook is loaded. It runs locally, costs nothing, and is handed to the model as data, never as instructions, so a function name in somebody’s clone cannot pass itself off as an order.
A second block says where the work stands: the branch, what changed, and how the last command ended.

Start the site. Look at it.
The agent proposes what to run from the project’s own manifest, and the card shows the program, the arguments and the port exactly. That card appears at every trust level. Once allowed, the page opens in the browser pane you both look at.
The model never types the address. The pane opens one loopback address: a dev server this app started.
run the launch page so I can see the pricing table

Edits that fail out loud.
An edit replaces one exact passage, only in a file this run has read, and only if the passage matches once. No match and two matches are both errors, never a guess.
The read is checked against the journal, not the conversation, so a long chat that got summarised still knows what it read. Changes shows what the agent left on disk.

Every commit waits for you.
git.commit and git.push always stop and ask, at every trust level. The agent writes the message, and you read it and the file list exactly as they will run.
In the source’s words, a commit is a model signing off its own work.
commit the pricing fix

Your files, your line endings.
Files lists every project folder, and a text file opens in a CodeMirror editor that saves exactly what you typed and keeps the file’s own line endings.
A replaced file over 4 KB is kept under .vectorbrain/versions, so Undo puts it back byte for byte.

- commit without asking
- push without asking
- edit a file it has not read
- guess between two matches
- choose what the dev server runs
- run a command after reading the web
None of these is a setting. Each is a check in the command bus, and each refusal is a sentence the agent can act on. How trust works here.
- reads outside the project
- the network
- Node child processes
- macOS and Linux
A command can still read your keys and send what it read out. Confining reads needs commands to run as a separate Windows account, which this build does not do. A Node tool cannot start its own child processes inside the box, which is why the dev server runs outside it. Off Windows there is no sandbox, and the shell and dev servers refuse to run.
Coding, in numbers.
- The code playbook
- Loads by /code, by itself in a code project, or when the judge is at least 0.7 sure the request is code. It brings the shell, git, the dev server and the repo map, and changes what is loaded, never what is allowed.
vb-cmd-skill/builtin/code.md; vb-agent/src/signal.rs; vb-agent/src/judge.rs · PLAYBOOK_BAR - Running programs
- Every conversation you start has the same ceiling, Exec. Your trust level decides what asks: a program asks at Always ask and Normal, and only god mode lifts that.
vb-agent/src/role.rs · PERSON_CEILING - Steps per run
- 150, one backstop for every conversation. The spending ceiling is the real bound.
vb-agent/src/role.rs · PERSON_STEPS - Repo map
- Tree-sitter, five grammars (Rust, TypeScript, TSX, JavaScript, Python). 12,000 characters, halved once the conversation has read files. Built once per run, cached by file size and time.
vb-map/src/render.rs - Where the work stands
- Branch, changed files, the last command with its exit code, and any running dev server, on every turn once the code playbook is loaded. No model call.
vb-cmd-fs/src/state.rs - Sandbox
- A write-restricted token, a job object that kills the whole process tree when the app closes, and an allowlisted environment, so keys exported in your shell do not reach a command.
vb-sandbox/src/lib.rs - Writable outside the project
- Toolchain caches only: .cargo, .rustup, npm-cache, pnpm and pip among them. sandbox.sweep takes every folder permission back off.
vb-sandbox/src/policy.rs - Shell timeout
- 60 seconds by default, 600 at most.
vb-cmd-fs/src/shell.rs - Edits
- Exact string, read first, match once. Up to 12 passages per call, all applied or none.
vb-cmd-fs/src/edit.rs - Always asks
- git.commit, git.push and dev.configure, whatever the trust level.
vb-bus/src/policy.rs - Kept versions
- 200 copies or 50 MB per folder, under .vectorbrain/versions.
vb-cmd-fs/src/versions.rs
The details,
for the careful.
Is there an AI coding agent that runs on Windows without WSL?
VectorBrain codes natively on Windows. Commands run inside a sandbox built from Windows’ own kernel objects, a write-restricted token and a job object, so there is no WSL2, Docker or virtual machine to set up.
Do I have to switch into a coding mode?
No. There is one kind of conversation. Type /code, open a conversation in a code project, or ask for code work and let the judge load the code playbook. It brings the tools and the know-how, not permission: running a program still asks at Normal trust, and every conversation gets the same 150 steps. One chat, and its playbooks
Can a command read my SSH keys?
Yes. The sandbox confines where a command writes, not what it reads, and it leaves the network open. Closing that needs commands to run as a separate Windows account, which this build does not do. What stands in front of it is the approval gate, the trust level and the journal. The shell, gated
Why does an npm script fail with spawn EPERM?
A tool built on Node, such as Vite, esbuild or an npm script, cannot start its own child processes inside the sandbox, because of how Windows sets the permissions on the pipes Node uses. A plain node script runs; one that starts other processes does not. The dev server runs outside the sandbox for this reason.
Can I take off the folder permissions the sandbox added?
Yes. The sandbox grants write permission on the toolchain caches and leaves it on, because stamping a large cache takes seconds. One command, sandbox.sweep, removes every folder permission the app granted. The next command puts back the ones it needs.
How does the agent see my running site?
It starts the dev server you confirmed and the page opens in the browser pane. It can read the page as text, handed to it as data. A screenshot of the pane for the agent is not built. The browser pane
Does it keep notes on the codebase between chats?
Build pages are files describing each feature and the paths it covers, rewritten when a commit changes those paths, so a new chat starts from them instead of rereading the code. They are built and tested, and have not yet been seen working in the app window.
Can two models race the same coding job?
Yes, with Versus. Each model works in its own fenced folder on the same prompt, neither sees the other, and you pick the winner. Versus
Does coding work on macOS or Linux?
Not yet. Off Windows there is no sandbox, and the shell and dev servers refuse to run rather than run unconfined. Download
Hand it the bug.
Read the diff.
One chat, in the folder you opened, on your machine, with the commit left for you.