What changes when nobody is watching
When you work with an AI agent on your computer, it asks for your permission every time it wants to do something sensitive. An agent scheduled for three in the morning can't ask anyone: what it is allowed to do is decided in advance, by its configuration. That's where three risks appear:
- It does more than you asked: writes where it shouldn't, runs commands or publishes something.
- It spends without limit, if it gets tangled up in a task it can't finish.
- It fails silently: it stops running and nobody notices for weeks.
Five rules for leaving an agent to work on its own
These are the rules we apply to the automations we build:
- One folder to write to. The agent can read what it needs, but it only writes to its own working folder. Never to your copy of the project.
- A closed list of tools. Read, search and edit, depending on the task. Running commands, never: whatever needs running goes in a separate step, without AI, in plain sight in the configuration.
- A spending cap on every step. If the agent gets tangled up, the step stops when it reaches the cap.
- What the agent claims, a step without AI checks. An agent saying it saved a file doesn't prove the file exists.
- If it stops working, you find out. The most expensive failure is the silent one: a task that hasn’t run for days must warn you just like one that fails.
agentic-pipelines: the engine that enforces these rules
agentic-pipelines is the open-source engine we built for this. Each automation is a pipeline.yaml file with its steps: shell steps for whatever can be done without AI, and agent steps, which use the Claude Agent SDK, for whatever needs judgment.
The rules don't depend on the agent behaving: the engine enforces them. Before every action the agent takes, it checks that the tool is allowed and that the agent writes inside its folder; if not, it denies the action and records it. Every run is saved with what each step did, its cost and its denials, and you can browse it in a local dashboard with pipelines web.
The automations are scheduled with the macOS scheduler (launchd), so for now it only runs on a Mac.
A dashboard to see what they did
pipelines web opens a local, read-only dashboard in your browser with all your automations: which ones are scheduled, which failed their last run, what each one cost and what every step did. If a task stops running, it shows up in red even when there's no error to report. And every run shows the actions the engine denied the agent: in one of our tests, the agent tried to read a file outside its folder and the engine blocked it, without the task failing.
Seven automations ready to use
In pipelines-starter we've published seven, tested with real data:
- site-checks: checks your websites every morning (errors, slow pages, certificates about to expire) and only alerts you when something is wrong.
- stale-prs: pull requests in your GitHub repositories that nobody has touched for days.
- issues-already-fixed: open issues that a merged commit already mentions, so they are probably done.
- dev-machine-doctor: the state of your development Mac: free disk, the biggest caches, open ports and forgotten processes.
- weekly-briefing: every Friday, an agent sums up your projects' week in plain language, for someone who doesn't read pull requests.
- docs-drift: an agent compares a repository's docs with its code and prepares fixes on a local branch.
- news-digest: every morning, an agent reads your RSS feeds and YouTube channels and writes a digest with content ideas.
All of them are read-only by default: none of them publishes, merges, closes or deletes anything. They leave a Markdown report and notify you on your Mac or, if you prefer, on your phone.
Install it in three steps
First, the engine:
git clone https://github.com/startcat/agentic-pipelines.git ~/agentic-pipelines
cd ~/agentic-pipelines && bun install
alias pipelines="bun run ~/agentic-pipelines/src/cli/index.ts"Then, the automations:
git clone https://github.com/startcat/pipelines-starter.git ~/pipelines-starter
cd ~/pipelines-starter && cp .env.example .envIf you'll use the ones with an agent, put your Anthropic API key in .env, as ANTHROPIC_API_KEY. Finally, install the ones you want, each with its own settings. For example, the website checks:
pipelines install site-checks --set urls="https://example.com"install checks that your Mac has everything it needs, saves the settings and schedules it. To try it without waiting until tomorrow, use pipelines run with the same options. Each automation has its own page on GitHub with every option.
What it costs
The engine and the automations are free. The four shell-only ones (site-checks, stale-prs, issues-already-fixed and dev-machine-doctor) don't use AI and cost nothing. The three that use an agent call the Anthropic API with your key and have a spending cap on every run. At API prices and with the model they come configured with (Sonnet), our test runs cost about $0.25 per weekly briefing, about $0.15 per news digest and between $0.20 and $0.35 per docs review, which only runs in weeks when the code changes.
If you want it cheaper, each agent can use a smaller model: changing model: sonnet to model: haiku in its file halves the price per token. In our test of the news digest, a run went from about $0.15 to $0.11. Check that the result is good enough for you.
Make your own
Each automation in the starter is a pipeline.yaml you can copy and adapt. pipelines validate checks the configuration before you schedule it, and the engine README explains how to write one from scratch in ten minutes.
If you'd rather we built it for you, connected to your company's tools, that's what we do in AI and automation.