Skip to main content
Create a small workspace, load two explicitly selected UTF-8 files as source context, and ask a model to identify the remaining release task. The application removes the temporary workspace after execution. Download the complete project, extract it, then run npm install and npm run check. Use npm start to execute the recipe with the requirements below.

Set up the project

Use Node.js ^22.18.0 or ^24.11.0. In an empty directory:
Running this recipe contacts OpenAI. Set OPENAI_MODEL to a compatible model your account can use; see model choices.

Run the reviewer

Save this as harness-workspace.ts:
harness-workspace.ts
Expect an answer identifying Verify migration example as outstanding, with references to README.md and CHECKLIST.md. The model has no shell or write tools and does not run the migration check itself.

Point it at your project

Replace the temporary-directory setup with an absolute project path and your explicit file list. Remove the demo’s writeFile and rm calls when the host does not own that directory. Keep requirements: ["filesystem:read"]: it authorizes binding the file context ability. fileContext reads only selected files under the canonical root and enforces retrieval bounds. Source files remain data, not trusted instructions. This grant is not OS isolation; the host process still has its normal filesystem permissions.

Add execution deliberately

To actually run a test or build, add an application-owned tool and grant its exact name. Choose a sandbox backend for the code’s trust level and define timeouts, output bounds, and ownership. A file snapshot does not capture running processes or external side effects. The file source is fetched at run time. Changes, missing files, invalid UTF-8, or exceeded context bounds can fail the run; inspect its status and reason instead of treating an empty answer as success.