Why the project boundary matters
AI is most useful when it can work with the real repository, but a broad host filesystem is the wrong security boundary. RepoTunnel registers explicit workspace roots and exposes those roots to AI by opaque workspace IDs rather than arbitrary absolute paths.
- Canonical project root stored locally by RepoTunnel
- Workspace-relative paths only
- Absolute paths and parent traversal rejected
- Symlink escapes rejected
- Common credential and private-key files protected
Read-only and read/write are separate from review policy
A workspace can be read-only or read/write. For writable projects, AI Review queues supported changes for local approval, while AI Auto can apply compatible operations immediately without removing the underlying security boundaries.
- Read-only always blocks writes
- AI Review preserves local Accept/Reject
- AI Auto removes repeated approval prompts for supported operations
- History and recovery remain active
Large repositories
RepoTunnel includes paged project inspection, paged directory listing, large-file range reads, and incremental search cursors so large codebases do not need to be transmitted or scanned in one giant operation.
- inspect_project_page
- list_directory_page
- read_file_range
- fast_search_files
Projects is the place to begin
Open an existing folder or clone a supported repository, then select that approved workspace in the Projects rail. The app shows its access, AI-change policy, command policy and current health.
The project setup panel reports the detected framework, package manager, dependencies and development command. Use Prepare project only when setup is needed and the proposed work is appropriate.
Work with files and context
The workspace editor opens files from the selected project, supports project/file search and preserves editing context across normal sessions. Project overview helps identify the repository before making changes.
Project Memory stores useful goals, decisions, preferences and intended next steps beside factual continuity state.