Safety and limits
What Lumis is allowed to touch, how code access and redaction work, the opt-in diagnostic sandbox, and how to verify the SDK yourself.
Boundaries
- Read-only.
read_onlyis the only accepted action mode. There is no executor. - Operator-owned access. Sources, queries, files and budgets are declared in YAML; the model cannot change them.
- Opt-in model. No model is called unless you enable the investigator for a run.
- Bounded work. Graph, query, request, tool, token, probe and time limits apply to every run.
- Visible uncertainty. Missing or degraded evidence stays unresolved; competing causes are not resolved by guesswork.
Code and Git access
Operators approve repository roots, the entities they belong to, and exact files. Traversal, symlinks, special, binary or oversized files, unapproved extensions and secret or dot directories are refused, and your application's modules are never imported. Git access is a fixed set of local read-only commands with external diff tools and hooks disabled. Commit subjects are excluded unless include_commit_subjects: true.
The diagnostic sandbox (opt-in)
probe runs model-generated Python in an ephemeral Docker container: a digest-pinned image, no network, no host mounts, no forwarded environment, a read-only root, an unprivileged user, dropped capabilities and CPU, memory, process and time limits. Approved files are copied in; nothing is downloaded. It is disabled unless investigator.sandbox.enabled: true.
Probe results are always degraded evidence: they cannot prove production behaviour or satisfy a terminal check. Containers share the host kernel, so use a dedicated, rootless development daemon, never a production one.
Redaction
Context sent to a model and stored receipts are redacted for common credentials and personal data patterns, without masking ordinary telemetry such as decimals, timestamps or IP addresses. It is a safety net, not a guarantee.
Verify the SDK yourself
git clone https://github.com/soloshun/lumis-sdk.git && cd lumis-sdk
uv sync --locked --all-groups
uv run ruff check . && uv run mypy src
uv run pytest
uv run bandit --recursive --severity-level medium --confidence-level medium src
uv audit --lockedThe test suite uses scripted models and mocked transports. It verifies contracts, budgets and failure behaviour, not diagnosis quality on live systems.
Source: Sandbox threat model ↗ in the SDK repository.