Welcome to Chapter 5!
In the previous chapter, Overlay Filesystem (Isolation), we learned how to let the AI write to files safely by giving it a "plastic sheet" (a temporary folder) to paint on.
But protecting files isn't enough. What if the AI tries to:
We need a way to freeze the AI the moment it tries to do something that requires your permission. We call this a Completion Boundary.
Imagine a self-driving car.
The Boundary: Suddenly, the car approaches a security checkpoint. The car cannot drive through it automatically. It stops immediately and waits for the driver (you) to show your ID card.
In our system:
If the background agent hits a boundary, it pauses execution and says, "I have done everything up to this point. I am waiting for you to press Accept to cross the checkpoint."
Let's visualize the moment the AI hits a boundary.
The logic for boundaries lives inside the canUseTool callback in speculation.ts. We check the tool name and decide whether to let it pass or stop it.
We categorize tools into safe and unsafe.
// speculation.ts
const SAFE_TOOLS = new Set(['Read', 'Grep', 'LSP']);
const BOUNDARY_TOOLS = new Set(['Edit', 'Write', 'Bash']);
Bash commands are dangerous. If the AI tries to run rm -rf, we must stop it. The AI doesn't actually run the command; it just prepares it.
// speculation.ts
if (tool.name === 'Bash') {
// 1. Save the command the AI WANTED to run
setAppState(prev => ({
boundary: {
type: 'bash',
command: input.command
}
}));
// 2. Pull the emergency brake
abortController.abort();
// 3. Tell the system why we stopped
return denySpeculation("Stopped at Bash Boundary");
}
Explanation:
When the AI says "Run npm test", we record "npm test" as the boundary and kill the process. When the user eventually accepts the suggestion, the system sees the boundary and puts npm test into the user's terminal.
Sometimes, whether an action is a boundary depends on the user's settings. If the user is in "Auto-Approve" mode, maybe we let the edit happen (into the Overlay). If they are in "Ask Me" mode, we must stop.
// speculation.ts
if (tool.name === 'Edit') {
// Check user settings
const canAutoAccept = appState.mode === 'auto_approve';
if (!canAutoAccept) {
// STOP! User wants to approve edits manually.
setAppState(prev => ({
boundary: { type: 'edit', file: input.file_path }
}));
abortController.abort();
return denySpeculation("Stopped: Edit requires permission");
}
// If we are here, we are allowed to continue (into the Overlay)
}
Explanation: This makes the system respectful. It does as much work as it is allowed to do, then stops exactly where human oversight is required.
If the AI tries to use a tool we don't recognize (maybe a new plugin), we treat it as a boundary by default for safety.
// speculation.ts
// Default fallback for unknown tools
setAppState(prev => ({
boundary: {
type: 'denied_tool',
toolName: tool.name
}
}));
abortController.abort();
return denySpeculation("Unknown tool boundary");
When the user finally accepts the suggestion (presses Tab), we look at the saved boundary to decide what to do.
Completion Boundaries act as the "Dead Man's Switch" for the speculation engine.
Tab.We have a powerful engine now. It predicts, it runs in the background, it isolates files, and it stops at safety boundaries.
But sometimes, the AI is just... wrong. Or chatty. Or hallucinates. We need a way to filter out "junk" suggestions before they ever flicker onto the user's screen.
Next Chapter: Heuristic Filtering & Suppression
Generated by Code IQ