The runner is a small Node CLI that installs .agentpack.zip files into .agentx/, enforces directory allowlists, and emits receipts per run.
Runner blocks file operations outside your allowlist. Agents declare required permissions. Some actions require approval flags to proceed.