
RunOnMine is a local control layer that lets AI assistants access your files, terminal, and applications while keeping all policy decisions, approvals, and audit logs on your own machine rather than in the cloud.
It enforces a local boundary so that remote AI services cannot execute dangerous actions without explicit local approval, making machine automation safer by making the boundary visible.
What happened
RunOnMine, a local-first Model Context Protocol (MCP) gateway, launched in public beta (v0.1.0-beta.1) for macOS, Linux, and Windows. It sits between an AI assistant and your machine, giving AI controlled access to files, terminals, browsers, and desktop applications while keeping execution, policy, credentials, approvals, and audit records on your device.
Why it matters
Instead of exposing SSH, a raw shell, or a public MCP listener to an AI service, RunOnMine enforces a local boundary that checks who is asking, what tool is being called, which resource it targets, and whether the action needs local approval before execution. This lets you use AI agents safely without granting them broad machine access or storing credentials remotely.
What to watch
RunOnMine is pre-release software; the beta is unsigned on macOS (ad-hoc signed only, not Developer ID signed or notarized) and unsigned on Windows (not Authenticode signed), so operating systems may warn on download. All artifacts include SHA-256 checksums and CycloneDX SBOMs; source builds remain supported for developers.
Ask the AI about this article →
RunOnMine addresses a friction point in AI agent design: how to let a cloud-hosted AI assistant (like Claude or ChatGPT) safely execute commands on your local machine without either giving it broad account authority or storing your credentials in the cloud. Traditional approaches—exposing SSH, running a public MCP listener, or trusting the AI service's own access controls—create a sharp security trade-off. RunOnMine inverts this by making the machine boundary visible and enforcing all policy locally.
The tool implements a multi-layer control model: connector identity (who is asking), resource scope (which directories/tools), policy rules (Safe, Developer, or Automation presets), and per-action local approvals. Shell processes run in a cleared environment; browser automation uses an isolated profile; secrets stay in the OS credential store. Importantly, RunOnMine is not a sandbox—it is a security boundary and approval system, meaning a compromised AI service could still cause harm if given write or execution authority, so the user must grant only the authority actually needed.
Being pre-release software (v0.1.0-beta.1) with unsigned artifacts on macOS and Windows, RunOnMine currently carries platform-level friction (Gatekeeper/SmartScreen warnings), but the project documents acceptance and security gates in machine-readable form and commits to a formal release process. For users who want to run local AI agents without storing credentials remotely or opening machine access to the internet, this reduces the friction significantly—though the onus remains on the user to set directory roots narrowly and choose the right policy preset.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

Google's AI search gave advice to call emergency services for users alone with an African, Indian, or Pakistan…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…

Israeli startup DataAgent Ltd