Runs packaged agents locally via a minimal CLI agent runtime with logs + exit codes.
Reads/writes local files for tasks like indexing, renaming, templating, and report generation.
Injects secrets/config into a local run (creates/updates .env or binds runtime env vars) without leaking values into logs.
Scans outputs/logs and redacts secrets/PII using rules + patterns before saving receipts.