Change Request boundary
Code-changing automation always creates a new branch and Change Request.
Security
xmode keeps risky work visible through explicit approval points, isolated execution, and reviewable Change Requests.
Code-changing automation always creates a new branch and Change Request.
Manual approvals can stop or revise plans before risky steps execute.
Local shell actions run in isolated worktrees and capture logs, artifacts, and structured output.
Agent providers are isolated behind typed adapter interfaces and mocked in tests.
Review posture