Safety Architecture & Planned Containment

A KVM can send input while the operating system is unavailable, so mistakes can affect the whole machine. The Comet prototype supports screen reading and input. Capability tiers, stale-frame checks, and audit controls below are proposed safeguards under development; they are not yet an enforced safety boundary.

Core Principle: Screen text is untrusted

Screen content can contain instructions aimed at an AI agent. The design requires the agent to treat that content as data and to use an independent operator instruction before taking consequential action. Enforcement of this rule is planned.

Planned Hardware Capability Tiers

Under the safety specification, every bootscry driver and session will operate within an explicit capability tier:

Tier 1: Read-Only

Under the specification, Tier 1 is designed to permit screen capture, OCR extraction, and video signal monitoring. HID injection and power commands will be blocked at the driver level.

Tier 2: Input Injection

Tier 2 is specified to permit keyboard typing and mouse movement within bounded coordinate spaces, while keeping hardware power cycling and reset lines blocked.

Tier 3: Power & Reset

Tier 3 is intended for devices with ATX power or reset control, with separate operator approval and audit logging. The reference Comet has no ATX board, so this tier cannot be tested on it.

Planned Execution Gates

1. Frame-Staleness Gate

Under the safety specification, the driver will verify that the current video snapshot is fresh before dispatching input. If the KVM video streamer is sleeping, stalled, or reports dropped HDMI sync, execution will halt immediately.

2. Confirm-Before-Click

The prototype has a click-text command that uses OCR word boxes. A separate confidence and freshness gate before every click is planned.

3. Bounded Audit Log

The proposed audit log would record actions in owner-only files and redact sensitive input. This behavior needs implementation and verification before it can be relied on.

4. Loopback Service Containment

The service prototype defaults to loopback. A documented, tested boundary for remote access, Host headers, and browser origins is part of the planned safety work.

Read configuration docsReview test evidence