Code

A coding agent on Windows.
It runs the tests. No WSL.

Any conversation can code. The code playbook brings a shell that runs inside a sandbox Windows itself enforces, a repo map and the dev loop. It fixes the thing, runs the tests, and leaves the commit for you to read.

VectorBrain with Tomas Reier, a developer agent, and the code playbook loaded. The request asks for the $9.50 plan’s annual price to be fixed and tested. Below it, five commands: two file reads, two exact edits and a shell run of node test/pricing.test.js, opened to show exit code 0 and “4 passed, 0 failed”. The answer explains the parseInt bug. On the right, src/pricing.js open in the Canvas’s code editor.

VectorBrain’s real interface, running on example data. The project and its code are invented.

01

A sandbox Windows enforces.

Every command runs under a write-restricted token inside a job object. Those are kernel objects, not a path check in the app. A command can write to the project and the toolchain caches, and everything it started dies when the app closes.

No WSL2, no Docker, no virtual machine. It does not confine what a command reads and it leaves the network open, and the app’s settings say both in the sandbox’s own words.

How the shell is gated

build the sitemap for the launch page

A coding run. The agent ran node scripts/build-sitemap.js, exit code 1: the sitemap was written into the project, and the script’s copy to the Documents folder failed with EPERM, operation not permitted. The agent says the write outside the project was refused and that it has not changed the script.
02

It reads a map before it starts.

Tree-sitter parses the project into a ranked list of files and the definition lines other files depend on, up to 12,000 characters, in front of every run once the code playbook is loaded. It runs locally, costs nothing, and is handed to the model as data, never as instructions, so a function name in somebody’s clone cannot pass itself off as an order.

A second block says where the work stands: the branch, what changed, and how the last command ended.

One chat, and its playbooks
From the “What the agent sees” receipt on the Workspace tab. What the last request weighed, block by block: base prompt, agent, project map at 690 tokens, tool definitions, the conversation and where the work stands, 18k in all. Under it, the map word for word as the model got it: a sentence on how to read it, then src/pricing.js with formatUsd, monthlyPrice and annualPrice at lines 6, 11 and 15.
03

Start the site. Look at it.

The agent proposes what to run from the project’s own manifest, and the card shows the program, the arguments and the port exactly. That card appears at every trust level. Once allowed, the page opens in the browser pane you both look at.

The model never types the address. The pane opens one loopback address: a dev server this app started.

The browser pane’s one loopback exception

run the launch page so I can see the pricing table

A coding run parked on an approval. The agent says nothing is set up to run yet, that package.json has a dev script, and that it starts once confirmed. The dev.configure card shows the name web, the program npm, the arguments run dev and port 5173, with Allow and Refuse.
04

Edits that fail out loud.

An edit replaces one exact passage, only in a file this run has read, and only if the passage matches once. No match and two matches are both errors, never a guess.

The read is checked against the journal, not the conversation, so a long chat that got summarised still knows what it read. Changes shows what the agent left on disk.

Why exact-string edits
The Changes tab in Settings: the unstaged diff on branch main, two files changed, src/pricing.js and test/pricing.test.js. One line replaces parseInt with Math.round(Number(monthly) * 100), and two assertions are added to the test.
05

Every commit waits for you.

git.commit and git.push always stop and ask, at every trust level. The agent writes the message, and you read it and the file list exactly as they will run.

In the source’s words, a commit is a model signing off its own work.

Why a commit always asks

commit the pricing fix

A git.commit approval parked in a conversation with the code playbook loaded, after git.status and git.diff. The card shows the input exactly as it will run: the message, starting “Price the annual plan from the whole monthly figure”, and the paths src/pricing.js and test/pricing.test.js, with Allow and Refuse.
06

Your files, your line endings.

Files lists every project folder, and a text file opens in a CodeMirror editor that saves exactly what you typed and keeps the file’s own line endings.

A replaced file over 4 KB is kept under .vectorbrain/versions, so Undo puts it back byte for byte.

Documents, decks and sheets
src/pricing.js open in VectorBrain’s code editor, with syntax colours: formatUsd, monthlyPrice and annualPrice, the last one now using Math.round(Number(monthly) * 100).
What it will not do

None of these is a setting. Each is a check in the command bus, and each refusal is a sentence the agent can act on. How trust works here.

What the sandbox does not close

A command can still read your keys and send what it read out. Confining reads needs commands to run as a separate Windows account, which this build does not do. A Node tool cannot start its own child processes inside the box, which is why the dev server runs outside it. Off Windows there is no sandbox, and the shell and dev servers refuse to run.

At a glance

Coding, in numbers.

The code playbook
Loads by /code, by itself in a code project, or when the judge is at least 0.7 sure the request is code. It brings the shell, git, the dev server and the repo map, and changes what is loaded, never what is allowed.vb-cmd-skill/builtin/code.md; vb-agent/src/signal.rs; vb-agent/src/judge.rs · PLAYBOOK_BAR
Running programs
Every conversation you start has the same ceiling, Exec. Your trust level decides what asks: a program asks at Always ask and Normal, and only god mode lifts that.vb-agent/src/role.rs · PERSON_CEILING
Steps per run
150, one backstop for every conversation. The spending ceiling is the real bound.vb-agent/src/role.rs · PERSON_STEPS
Repo map
Tree-sitter, five grammars (Rust, TypeScript, TSX, JavaScript, Python). 12,000 characters, halved once the conversation has read files. Built once per run, cached by file size and time.vb-map/src/render.rs
Where the work stands
Branch, changed files, the last command with its exit code, and any running dev server, on every turn once the code playbook is loaded. No model call.vb-cmd-fs/src/state.rs
Sandbox
A write-restricted token, a job object that kills the whole process tree when the app closes, and an allowlisted environment, so keys exported in your shell do not reach a command.vb-sandbox/src/lib.rs
Writable outside the project
Toolchain caches only: .cargo, .rustup, npm-cache, pnpm and pip among them. sandbox.sweep takes every folder permission back off.vb-sandbox/src/policy.rs
Shell timeout
60 seconds by default, 600 at most.vb-cmd-fs/src/shell.rs
Edits
Exact string, read first, match once. Up to 12 passages per call, all applied or none.vb-cmd-fs/src/edit.rs
Always asks
git.commit, git.push and dev.configure, whatever the trust level.vb-bus/src/policy.rs
Kept versions
200 copies or 50 MB per folder, under .vectorbrain/versions.vb-cmd-fs/src/versions.rs

The details,
for the careful.

Is there an AI coding agent that runs on Windows without WSL?

VectorBrain codes natively on Windows. Commands run inside a sandbox built from Windows’ own kernel objects, a write-restricted token and a job object, so there is no WSL2, Docker or virtual machine to set up.

Do I have to switch into a coding mode?

No. There is one kind of conversation. Type /code, open a conversation in a code project, or ask for code work and let the judge load the code playbook. It brings the tools and the know-how, not permission: running a program still asks at Normal trust, and every conversation gets the same 150 steps. One chat, and its playbooks

Can a command read my SSH keys?

Yes. The sandbox confines where a command writes, not what it reads, and it leaves the network open. Closing that needs commands to run as a separate Windows account, which this build does not do. What stands in front of it is the approval gate, the trust level and the journal. The shell, gated

Why does an npm script fail with spawn EPERM?

A tool built on Node, such as Vite, esbuild or an npm script, cannot start its own child processes inside the sandbox, because of how Windows sets the permissions on the pipes Node uses. A plain node script runs; one that starts other processes does not. The dev server runs outside the sandbox for this reason.

Can I take off the folder permissions the sandbox added?

Yes. The sandbox grants write permission on the toolchain caches and leaves it on, because stamping a large cache takes seconds. One command, sandbox.sweep, removes every folder permission the app granted. The next command puts back the ones it needs.

How does the agent see my running site?

It starts the dev server you confirmed and the page opens in the browser pane. It can read the page as text, handed to it as data. A screenshot of the pane for the agent is not built. The browser pane

Does it keep notes on the codebase between chats?

Build pages are files describing each feature and the paths it covers, rewritten when a commit changes those paths, so a new chat starts from them instead of rereading the code. They are built and tested, and have not yet been seen working in the app window.

Can two models race the same coding job?

Yes, with Versus. Each model works in its own fenced folder on the same prompt, neither sees the other, and you pick the winner. Versus

Does coding work on macOS or Linux?

Not yet. Off Windows there is no sandbox, and the shell and dev servers refuse to run rather than run unconfined. Download

Hand it the bug.
Read the diff.

One chat, in the folder you opened, on your machine, with the commit left for you.