Run untrusted agents in a hardware-isolated Linux microVM on macOS — a security boundary built on Apple's Virtualization.framework
Prebuilt squashfs block-image rootfs provider for vmette
Shared boot-asset (kernel + initramfs) discovery for vmette binaries
OCI/Docker image rootfs provider for vmette
Tarball-over-HTTP/file rootfs provider for vmette
The default rootfs-provider registry for vmette (dir + squashfs + tar + OCI, in resolution order)
Wire contracts shared across the vmette workspace: the guest computer-use vocabulary and the vmetted UNIX-socket protocol