Windows
Install and run a worker on Windows — the Scheduled Task, agents installed per user, and what the OS sandbox does not cover on Windows.
node scripts/package-worker.mjs
powershell -ExecutionPolicy Bypass -File installers\windows\install-worker.ps1- Autostart: a per-user Scheduled Task at logon; if the worker stops it is started again within a minute.
- Credentials: Windows Credential Manager.
- Uninstall:
installers\windows\uninstall-worker.ps1(add-RemoveDatato delete configuration and credentials).
The installer was run for real on Windows 11 — install, restart and uninstall. Starting at sign-in was not exercised.
Agents on Windows
Install agents for your own user (for example with npm) and sign in once from a terminal. The worker finds
them on your PATH. Windows .cmd shims are validated so arguments cannot inject commands.
Sandbox
Windows has no OS sandbox for agents. With the sandbox policy preferred the task runs unsandboxed and the
recovery notes say so; with required it stops with RECOVERY_REQUIRED. Isolation relies on project-path
mapping, the environment allowlist and the agent's own permission mode — see Worker security.