4 Oct

System design: an agent that proposes, and I publish

Status: in design. Nothing is built yet; this entry is the system design.

The problem

I build client systems in private repos. Showing them means copying the story by hand into this portfolio and into a public GitHub repo, and I fall behind. Letting an AI write straight to the site is no better: it could publish a mistake, or leak a client name or a secret.

The design

System design: a push wakes the agent, which reads and proposes through an MCP server; proposals pass a secret scan and wait for approval before reaching the site or the public repo
  • The agent only proposes. It reaches the site through an MCP server whose tools can read content and propose changes, and nothing else.
  • A secret scan runs before anything is queued, so a client name or a key never reaches my inbox, let alone the public repo.
  • Only I publish. Approving, editing or rejecting happens in my own admin, and only that session can write to the live site or the public repo. The rule is enforced by the server, so the agent cannot skip it.
  • It sleeps between pushes. A push, a daily schedule, a Run now button or a chat message wakes it. The rest of the time it costs nothing.

The repo with the same design is at github.com/ALPHAbilal/portfolio-agent.