A runtime/ folder that teaches Claude Code and Codex to discover, connect to, and use your systems, with clear rules on what they can do on their own. No server, no paid API.

Four policy files, diagnostic and verification scripts, bridges, a guard, and 7 tested recipes. Copy them into your project and your agents will follow the same rules. The files inside runtime/ are written in Portuguese; your agent reads them and answers in your language.
Before saying "impossible," the agent climbs the ladder API → MCP → CLI → SDK → computer use → local bridge and uses the most stable available path.
Reading is unrestricted; it changes files and tells you; sending requires asking first; spending money or deleting data is prepared only. .claude/settings.json already blocks rm -rf.
Uses the Claude Code and Codex CLI you are already logged into. No paid API is required. Ollama local models are optional.
Each step has a file. Every action passes through POLITICA.md.
Tool map: one line per system, with the access path, level, and test date. A system without an entry is not used.
Autonomy levels N0 to N4 and the ceiling for each action type. "Always allow" never exceeds the ceiling.
Which model for which task (super, top, executor, smaller). Start with the smallest model that can handle it.
The cycle, the getting-started order, and the access ladder with examples.
| Level | Path | Example | Stability |
|---|---|---|---|
| 1 | Official API | ERP API | high |
| 2 | MCP | claude mcp list | high |
| 3 | CLI | codex exec, gh, git | high |
| 4 | SDK / library | npm/pip package | medium |
| 5 | Computer use | automated browser, on-screen clicks | low |
| 6 | Local bridge | CSV export, folder, SQLite database, local port | medium |
| 7 | Reverse engineering | observe the app running to find the access path | lab only: breaks at the next update |
| Action | Ceiling | In Claude Code | In Codex |
|---|---|---|---|
| Read a file, page, or spreadsheet | N4 | allowed | -s read-only |
| Create/change a project file | N3 | acceptEdits | -s workspace-write |
| Command that changes the system | N2 | asks for confirmation | no auto-approval |
| Send (email, message, post, push) | N2 | asks for confirmation | no auto-approval |
| Spend money or credits | N1 | blocked | do not execute |
| Delete data / production | N1 + backup | blocked (rm -rf) | do not execute |
N0 only chats · N1 prepares and the human executes · N2 executes after asking · N3 executes and tells you · N4 executes without notice. The agent does not change its own rules: it proposes a row in the "Learning" table of POLITICA.md, and you approve it.
Linux or Mac. On Windows, use WSL. The diagnostic only reads local versions and status: it does not call a model or API.
Runs the diagnostic, the MCP bridge, and the observe and verify scripts.
node --versionAt least one of the two, logged in through your subscription.
npm i -g @anthropic-ai/claude-code npm i -g @openai/codex codex login
Free local models for lightweight tasks. The diagnostic shows whether it is installed.
ollama --versionEach recipe ends with proof: a command and the output that should appear. If the proof does not match, the step is not ready.
Shows what is installed and logged in: Node, Claude Code, Codex, and Ollama.
git clone https://github.com/inematds/inema-agent-runtime meu-projeto cd meu-projeto node runtime/scripts/doctor.mjs # proof: PRONTO at the end
Open claude (or codex) in the folder and ask it to climb the ladder level by level. Only add an entry after a test has passed.
# inside claude or codex: Read runtime/LEIA-ME.md and help me fill in CAPACIDADES.md for my work.
CLI bridge (level 3). By default, Codex only reads; changing files (N3) requires passing workspace-write.
chmod +x runtime/pontes/codex-exec.sh runtime/pontes/codex-exec.sh "Reply with PONG only" # proof: PONG runtime/pontes/codex-exec.sh "Create notas.txt with the word OK" "$PWD" workspace-write
Planner (opus), executor (sonnet), and reviewer (haiku), defined in .claude/agents/. Each uses the model it needs, so you get more out of your quota.
claude -p "Use the team (planner, executor, reviewer). Task: create saudacao.txt with the sentence 'Olá, comunidade INEMA'. Finish with the reviewer's response." # proof: saudacao.txt contains the sentence and the response ends with APROVADO
The ERP or calendar exports a file; the bridge reads that file and provides it to the agent as a read-only tool. Dependency-free MCP server, already registered in .mcp.json.
node runtime/pontes/mcp-modelo/server.mjs --selftest # proof: tools: 2 and TOTAL: R$ 856.00 claude mcp list # ponte-modelo … Connected codex mcp add ponte-modelo -- node "$PWD/runtime/pontes/mcp-modelo/server.mjs"
Several Claude sessions at once, each with a name, role, and model. Mark the folder as trusted once. Each session uses your quota.
claude --bg --permission-mode plan --name reviewer "Read runtime/POLITICA.md and answer in one line what the ceiling for 'Enviar' is." claude --bg --model sonnet --name executor "Create resumo.md with 3 lines about what this kit is." node runtime/scripts/observar.mjs # table with id, type, name, and state
For systems that exist only as websites. Reading a page is N4; filling in or sending requires asking first; never make payments.
npm i -g agent-browser agent-browser install agent-browser open https://example.com agent-browser get title # proof: Example Domain agent-browser close
The agent only finishes when the goal's command → expected output criteria pass, not when it thinks it is done.
node runtime/scripts/verificar.mjs runtime/exemplos/goal-exemplo.md # proof: 4/4 criteria OK and exit 0; break a criterion and the line becomes FALHA
With several agents running at once, the guard catches two risks before they happen, and never decides on its own: it asks (N2). Collision: before editing a file another session edited, or that changed externally (Codex, editor, another person) in the last 30 min. Blast radius: before rm or git clean, it shows how many files would be deleted, their size, and the first paths. It is already enabled in this kit through .claude/settings.json; to bring it to another project, use one of these methods: the command below or copy the hooks block from .claude/settings.json and change the path.
# guard in another project (this session only) claude --plugin-dir /caminho/do/kit/runtime/mods/runtime-guarda # optional dashboard: in the session, type /painel claude --plugin-dir runtime/mods/runtime-painel claude plugin test runtime/mods/runtime-painel # proof: 1 pass
The dashboard lists claude --bg sessions (name, state, minutes), with Refresh and Stop: only your click stops a session. INEMA_COLISAO_MIN=60 changes the collision window. Codex does not yet have an equivalent "before editing" hook: collision protection covers Claude sessions and detects edits made by Codex through the file date.
The example files in runtime/exemplos/ simulate the community's two most common cases: a system without an API that exports a spreadsheet.
The ERP exports a sales CSV. The bridge exposes the resumo_vendas tool; the R2 team puts together the summary and the reviewer checks the totals.
# runtime/exemplos/erp-vendas.csv data,cliente,produto,quantidade,valor_unitario 2026-10-01,Mercado Sol,Café 500g,10,18.50 # bridge selftest → TOTAL: R$ 856.00
The schedule lives in a spreadsheet. The listar_horarios_livres tool returns only livre rows, filtered by date and professional.
claude -p "Use the listar_horarios_livres tool from ponte-modelo and list the free appointment times for 2026-10-07." # proof: 08:00 (Dra. Ana) and 16:00 (Dr. Bruno)
To use it with your system: set PONTE_DADOS=/caminho/da/exportacao in the env field of .mcp.json, change the columns used in run(), keep the tools read-only, and note the bridge in CAPACIDADES.md with the test date.
Each phase closes only when its proofs pass. The proofs run for each version are listed in CHANGELOG.md.
codex-exec.sh bridge, R1 and R2 recipes, and blocks in .claude/settings.json. Proofs run on Linux through the subscription.observar.mjs, verificar.mjs, and recipes R3 to R6.runtime-guarda mod (collision and blast radius, already enabled in the kit), optional runtime-painel mod with /painel, and recipe R7.