For AI agents

Give your agent a computer, within limits.

Today an agent that controls a machine usually gets a whole shell. With Vigil MCP it gets the capabilities the device allows, and nothing else.

Example session

The model can ask. The device answers.

Here Claude works through Vigil MCP on a device that allows screenshots and quick scans, and asks before restarting. When Claude reaches for something outside that list, the device refuses and Claude tells the user why.

user

My laptop is slow. Check it and clean up whatever you find.

claude → vigilscreenshot ALLOW
defender.scan {"type": "quick"} ALLOW · no threats found
claude → vigilshell.exec {"cmd": "Remove-Item $env:TEMP\* -Recurse"} VETO
capability not allowed on this device
claude

The quick scan found no threats, and the screenshot shows 31 browser tabs using most of the memory. I could not clear temporary files: this device does not allow it. If you want me to do that, allow a cleanup capability on the laptop itself.

Tools, generated from policy

The agent only sees what it may use.

Vigil MCP turns each allowed capability into one tool with a strict input schema. Denied capabilities are not listed, so the model does not plan around them.

// mcp config
{
  "mcpServers": {
    "vigil": {
      "command": "vigil-mcp",
      "args": ["--device", "WS-ACCOUNTING-07"]
    }
  }
}

// tools the model receives
screenshot()
defender_scan(type: "quick")
restart(delay_s: 0..3600)   // asks the user first
Why it belongs outside the model

Instructions can be argued with. A policy cannot.

A system prompt that says "never delete files" lives inside the conversation, where a web page, an email or a document can talk the model out of it. The device policy lives on the machine. Whatever the model is persuaded to try, the agent checks it against a list the model cannot see or change.

That lets you hand real work to an agent, like taking screenshots, running scans or restarting after hours, without handing over the machine.