Why Caddy runs as a host service installed from Caddy's signed official APT repository, not as a Podman container, on my personal services platform. And why an explicit administrator runbook replaces a premature automated wrapper.
Security
Greywall's built-in pi profile leaves the agent's persistence vectors writable. Analysis of the gaps (network, inaccurate XDG paths, overly broad allowWrite) and a corrective denyWrite profile, with the limits the sandbox cannot cover on its own.
pi-secured-setup v1.1.0 maps against the OWASP AI Agent Security Cheat Sheet. HMAC-chained audit log, bash exfiltration detection, rate limiting, prompt injection scanner, and 14 Dependabot advisories closed.