Operating checklist
Run the open-source tool locally before connecting sensitive projects.
Review each repo's license, install path, and security notes.
For Sweetgrass, decide which projects and GitHub repos the UI may read.
For Marsh, validate runner isolation, teardown, cache boundaries, and secret handling.
For Lantern, keep local machine credentials and agent CLI configuration under the operator's control.
For Quill, review source access, exclusions, provenance, and the private-preview boundary before connecting an archive.
How to proceed
Start with the public repo for the tool. Connect sensitive repos only after the team has reviewed permissions, local state, CI secrets, and teardown behavior.