Skip to main content

Keep one-click demos

Drop an untrusted file into a sealed cell, get an artifact back. Every demo runs with no browser and expects 0 CONNECT. If the audit journal ever shows an outbound connection, the run fails closed: the session is frozen with agent_paused_reason: ebpf_deny and the API returns 409.

DemoInputArtifactPage
pdf-briefPDFbrief.mdpdf-brief.md
contract-clausescontract PDFclauses.mdcontract-clauses.md
security-questionnairequestionnaire PDFanswers.mdsecurity-questionnaire.md
meeting-actions.txt / .vtt transcriptactions.mdmeeting-actions.md
log-triage.log / .txttriage.mdlog-triage.md
sbom-summaryCycloneDX / SPDX / SARIF JSONsummary.mdsbom-summary.md
csv-clean.csvclean.csv + report.mdcsv-clean.md

One API for all of them​

./scripts/keep-demo.sh list # what this runtime offers
./scripts/keep-demo.sh csv-clean # built-in sample
./scripts/keep-demo.sh log-triage app.log # your own file
SurfacePath
Console/app/keep (pick a use case)
Runtime APIGET /v1/demos, POST /v1/demos/{id} (multipart field file)
fabricd proxyGET /api/demos, POST /api/demos/{id} (JWT)
Registryagent-runtime/src/demos.rs (DEMOS)
Buildersagent-runtime/src/demo_builders.rs

Testing​

bash agent-runtime/tests/demos-ci.sh # real runtime + FluxVM stand-in; needs node 20, python3, curl (pdftotext for the PDF demos)

See STATUS.md for what this does and does not prove.

What "extractive" means​

The guest runs one fixed command to pull text out of the upload (pdftotext, or head for text formats). The summary is then built on the host with plain string handling. No model is called, nothing found in the file is executed, opened or sent, and every untrusted line is defanged before it lands in markdown. A model-written summary would need a model socket, which these demos deliberately do not use.

Adding a use case​

Most use cases need no Rust. Describe one as a pack.json (an extractor plus a few summary rules), or fill in the form at /app/keep → Deploy your own use case, then:

./scripts/keepctl deploy ./my-usecase --test

See Tutorial 19 and the field reference in PACKS.md. A use case that needs code is a TypeScript agent pack that runs inside the cell.

To add a built-in (shipped with the runtime) instead: add a builder to demo_builders.rs with a unit test, a DemoSpec to DEMOS in demos.rs, then examples/keep-agents/<id>/ (with "kind": "builtin") and docs/keep/demos/<id>.md. The console picker, the fabricd proxy and keep-demo.sh pick it up without further changes.

Honesty: evidence class stays software-test; zero CONNECT is a Keep audit claim, not "the operator cannot read the cell".