Protected paths
Traversal attempts and edits outside the allowed workspace are rejected before a command runs.
Latorium limits what automated work can touch, strips dangerous process settings, and keeps an audit trail you can read.
Traversal attempts and edits outside the allowed workspace are rejected before a command runs.
Interpreter preload variables are removed and operations are checked before local execution.
Credential-shaped output is hidden before it becomes saved context or a shareable report.
A failed change can restore its affected dependency group without throwing away unrelated passing work.
The release gate scans the exact VSIX contents for secrets and unexpected bundled files.
Drafts are not silently applied, saved memory is editable, and the workspace audit log remains inspectable.
Using a cloud agent sends selected context to its provider. Latorium Local Coder sends nothing off this machine.
A corrupt index is quarantined and rebuilt. A schema from a newer Latorium version is left intact. Stale retrievals are invalidated after file changes, and repair loops stop when further attempts stop improving the result.