Public Apache-2.0
Inspect the source and evaluate locally.
HELM AI Kernel checks consequential tool calls before side effects run, records the verdict, and leaves evidence that can be verified later. Unknown MCP servers stay quarantined until a human approves them.
Inspect the source and evaluate locally.
Consequential calls are checked before dispatch.
Verdicts leave a reviewable record.
Toggle the conditions that decide whether the request is allowed, escalated, or denied. The receipt changes with the verdict.
Fail-closed: human approval, connector scope missing for iam_permission_change.v3.
rcpt-demo-f703476e The Kernel page gives builders a straight path from public source to local evaluation to receipt review.
After the model session ends, the record still shows what was requested, what HELM decided, and what evidence belongs with the decision.
Changed verdict - different digest.
See sample receipts and EvidencePacksBring one tool call, one policy, and one receipt requirement to the boundary.