Abstract
A system is described herein for enabling a cloud-hosted artificial intelligence (AI) agent to securely execute a small, explicitly governed, fully audited set of local actions on an operator workstation. A hardened desktop bridge turns the workstation into a trusted proxy that extends the agent to day-zero, greenfield, and network-isolated devices through serial, Universal Serial Bus (USB), and local area network (LAN) paths during initial bring-up. Least privilege is maintained through a sandboxed renderer, a narrow inter-process boundary, a runtime fail-safe command allowlist, operating system (OS) keychain credential isolation, unconditional shell-metacharacter blocking, and an append-only audit log. The agent can therefore discover, provision, and troubleshoot locally attached or isolated devices without receiving a general-purpose shell or direct cloud access to those devices.
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 License.
Recommended Citation
Rydzanych, Marian Volodymyrovych and Muralitharan, Goudam Jaganmohan, "METHOD FOR SECURE, LEAST-PRIVILEGE LOCAL EXECUTION OF CLOUD-HOSTED ARTIFICIAL INTELLIGENCE OPERATIONS ON DAY-ZERO AND NETWORK-ISOLATED DEVICES VIA A HARDENED ENDPOINT BRIDGE", Technical Disclosure Commons, (September 07, 2026)
https://www.tdcommons.org/dpubs_series/11610