Boring Infra Co.

Pico Use Cases

Security observability workflows for AI-assisted development.


Untrusted input to production paths

Detect when external content — like a public GitHub issue — can reach production mutation authority through your agent toolchain:

Public GitHub Issue → GitHub MCP → OpenCode → Bash → Cloudflare Token → Production Worker

Pico maps these chains with evidence so you can see the full path, not just individual permissions.

Permission reality check

Understand what your agent can actually do versus what documentation promises. The security graph connects agents, tools, capabilities, and authority sinks.

Credential reachability audit

See which tokens your agent environment can reach — stored as fingerprints only, never as secrets:

pico init
pico scan
pico history --json

Pre-deployment agent review

Scan your workspace before granting broad MCP or tool access to a new agent configuration:

cd your-project
pico init
pico scan
# review findings before deploying agent config

Compliance evidence

Build a local, verifiable security graph of your agent environment. No cloud upload, no Pico account — the evidence stays on your machine.

Scan diffing over time

Track how your agent environment changes between scans:

pico scan
# ... make changes to agent config ...
pico scan
pico diff --json