Give your agent a computer, within limits.
Today an agent that controls a machine usually gets a whole shell. With Vigil MCP it gets the capabilities the device allows, and nothing else.
The model can ask. The device answers.
Here Claude works through Vigil MCP on a device that allows screenshots and quick scans, and asks before restarting. When Claude reaches for something outside that list, the device refuses and Claude tells the user why.
My laptop is slow. Check it and clean up whatever you find.
defender.scan {"type": "quick"} ALLOW · no threats found
capability not allowed on this device
The quick scan found no threats, and the screenshot shows 31 browser tabs using most of the memory. I could not clear temporary files: this device does not allow it. If you want me to do that, allow a cleanup capability on the laptop itself.
The agent only sees what it may use.
Vigil MCP turns each allowed capability into one tool with a strict input schema. Denied capabilities are not listed, so the model does not plan around them.
// mcp config { "mcpServers": { "vigil": { "command": "vigil-mcp", "args": ["--device", "WS-ACCOUNTING-07"] } } } // tools the model receives screenshot() defender_scan(type: "quick") restart(delay_s: 0..3600) // asks the user first
Instructions can be argued with. A policy cannot.
A system prompt that says "never delete files" lives inside the conversation, where a web page, an email or a document can talk the model out of it. The device policy lives on the machine. Whatever the model is persuaded to try, the agent checks it against a list the model cannot see or change.
That lets you hand real work to an agent, like taking screenshots, running scans or restarting after hours, without handing over the machine.