Offline context and injection defense
Discover local sources, apply policy and token budgets, compile a provenance-bearing bundle, and keep untrusted source content from becoming instruction authority.
CIGAR Honey · 0.9.1 alpha
Compile governed context, coordinate two agents, recover ambiguous effects, and replay evidence with a deterministic, credential-free developer preview built for Apple-silicon macOS.
Honey is the first bounded CIGAR profile for hands-on local evaluation.

Alpha developer preview. Unsupported evaluation software; not production-qualified, signed, or notarized.
RELEASE FACTS
WHY 0.9.1
Honey 0.9.1 incorporates issues discovered during a 200-iteration proof of concept on a working security testing platform—100 runs with CIGAR and 100 without. The release focuses on persistence, restart behavior, retrieval, duplicate-content handling, correlation, and bounded local storage behavior.
WHAT DEVELOPERS CAN EVALUATE
Discover local sources, apply policy and token budgets, compile a provenance-bearing bundle, and keep untrusted source content from becoming instruction authority.
Fork private work, issue a signed and attenuated handoff, accept it once, record a typed result, and merge against an exact base.
Record intent before dispatch, preserve ambiguity as UNKNOWN, reconcile or compensate, and replay retained observations without repeating the effect.
Connect a local agent workflow through the packaged MCP server and Claude Code adapter while retaining CIGAR's policy and evidence boundaries.
INCLUDED SURFACES
Honey selects the local capabilities needed to evaluate CIGAR's core operating model without presenting experimental or deferred work as release functionality.
The experimental dashboard, Go SDK, vector retrieval, public npm package, and public crates.io package are not selected Honey features.
PUBLISHED PYTHON SDK
The developer-preview SDK is available for Python 3.14. The distribution name is hol-cigar; application code imports the cigar_sdk namespace. The full Honey desktop archive remains a separate release.
python3.14 -m pip install "hol-cigar==0.9.1"
python3.14 -c 'import cigar_sdk; print(cigar_sdk.__version__)'QUALIFICATION
The 0.9.1 cut binds one clean source commit and tag to an exact 13-file Honey inventory. The release contracts, checksums, documentation, Python SDK checks, release-tool tests, Rust workspace tests, and warnings-denied Clippy passed. The public artifact verifier returned passed-artifact-integrity. The exact hol-cigar wheel and source distribution passed strict metadata validation and clean offline Python 3.14 installs in a disconnected, non-admin Apple-silicon macOS VM, including the 45-operation surface, shared fixture, and both entry points.
Artifact integrity and installability do not establish production readiness, security certification, or a general token-efficiency or accuracy improvement.
LIMITATIONS
Honey does not claim release support for the deferred capabilities and platforms below.
Honey's authority and integrity controls operate within one local-user trust boundary. They are not process isolation between mutually hostile programs running as that user.
HONEY FAQ
hol-cigar is the Python distribution name used by package tooling. cigar_sdk is the stable Python module imported by application code.
No for the packaged deterministic demos. They are designed to exercise CIGAR without model-provider credentials or network access.
No. Honey 0.9.1 is unsupported alpha evaluation software and is not production-qualified, signed, or notarized.
Vector retrieval is not selected for this release profile. Exact, path, symbol, graph, and lexical retrieval remain available.
No. Dashboard work may exist in proof-of-concept environments, but it is not selected, packaged, or advertised as a Honey 0.9.1 release capability.
Those platforms are not qualified for this release. The selected target is Apple-silicon macOS.
CIGAR UPDATES
Join the HOL email list for CIGAR release notes, SDK updates, and new developer resources.