Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This guide covers 57Ajay/Scout, the GitHub project that gives AI agents remote VM control, including shell execution and file operations. It is not Microsoft Scout or Docker Scout. Scout’s own documentation describes native and Docker Compose deployment, but its defaults are broad: filesystem access can start at /, and command policy can default to allow. A safer setup narrows the host, paths, callers, and commands before connecting an agent.

Choose a deployment path based on what Scout must access

Neither running in Docker nor installing natively creates a complete security boundary by itself. The practical difference is which host capabilities you hand to Scout.

Deployment Host privilege and filesystem scope Use it when
Native build Scout runs with the installing user’s access to files and any Docker or Kubernetes capabilities available to that user. You need a direct host installation and can run Scout as a dedicated, low-privilege account with only necessary access.
Docker Compose You can mount a selected host directory read-write. The project’s example also includes mounts for the host Docker socket and kubeconfig; the repository warns that the socket mount is root-equivalent on the host. You want to scope file access to a chosen directory and can omit unneeded mounts. Compose is not a safe boundary if you pass through powerful host interfaces.

For either option, use a dedicated machine or VM when possible, run with a non-administrator account, and avoid placing unrelated secrets or workloads within reach. These are deployment precautions, not a claim that Scout itself provides an independently validated sandbox.

Set up Docker Compose with only the access you need

  1. Clone the Scout repository and change into its directory.

    What’s actually slowing this PC down?

    Pick the symptom - the matching free tool is one click away.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    #1 Best Overall
    Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
    • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
    • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
    • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
    • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
    • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  2. Copy .env.example to .env.

  3. Set AUTH_TOKEN to a strong, unique secret. Set HOST_MOUNT to one deliberately limited project directory, rather than a home directory, broad data directory, or filesystem root.

  4. Inspect the Compose configuration and remove the host Docker socket mount unless the agent’s task specifically needs Docker control. The repository states that “The Docker option with the socket mounted is root-equivalent on the host.” Treat that mount as a grant of host-level power, not as an ordinary container feature. Remove the kubeconfig mount too unless Kubernetes access is required.

  5. Start the service with docker compose up -d --build.

  6. Before allowing external connections, configure TLS through the bundled Caddy option or Scout’s TLS certificate settings. Do not publish a plaintext token or send it over an unprotected connection.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build natively only with a deliberate account boundary

The repository documents a native build requiring Go 1.23 or newer. It describes building with go build -o scout ., preparing a configuration file, and starting with ./scout --config scout.yaml. Running natively means Scout inherits the permissions and reachable resources of the account that starts it; limit that account’s filesystem and group access before launching the service.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The project also documents a one-shot installer that uses sudo to install a service running as the user’s account. The use of sudo for installation does not make the running service isolated. Review what the installer changes and what user account the service uses before choosing this path.

Replace permissive defaults before connecting an agent

Scout’s repository documents filesystem.roots defaulting to ["/"] and policy.default defaulting to allow. In its own warning, the project says: “With filesystem.roots: ["/"] (the default) and default-allow policy, an approved agent can do anything you can.” Do not leave those defaults in place for a constrained environment.

Limit filesystem roots

Set filesystem.roots to the smallest project directory the workflow needs. For example, if work belongs in a single repository, grant that repository rather than its parent directory or the whole machine. Check any Docker bind mounts as well: a narrow Scout configuration cannot make a broad host mount narrow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose an explicit command policy

For an interactive first run, the repository documents policy.default: ask, which sends commands for approval. For a more restrictive unattended setup, use policy.default: deny and define explicit allow rules for required commands. Default-allow is convenient but means ordinary commands may run without a prompt. Scout’s built-in dangerous-command guard escalates listed destructive patterns for approval; it does not make broad allow rules safe.

Review protected paths

The project documents protected paths including .ssh, .aws, .gnupg, kubeconfig, *.pem, *.key, .env*, /etc/shadow, and sudoers. Access—including reads—to these paths is escalated. Review the list for your environment and add organization-specific secret locations; a protected-path control is not a reason to expose those directories unnecessarily.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect the service endpoint and token

According to Scout’s documentation, every endpoint requires the bearer token, including health and dashboard routes. That authentication requirement does not make a publicly reachable, unencrypted service safe.

Verify the boundary before handing control to an agent

  1. Confirm the active filesystem roots cover only the intended work area, and that no parent directory or sensitive mount expands the scope.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Check the effective command policy: use ask for approval-led use, or deny with explicit allow rules for locked-down automation.

  3. Inspect container mounts and remove Docker socket, kubeconfig, and other host interfaces unless the workflow needs them.

  4. Confirm protected paths include the secrets relevant to your host, and that the token is not exposed in configuration management, logs, or source control.

  5. Test access with a non-sensitive task and verify that disallowed paths and commands are denied or escalated as intended before granting a real agent access.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These steps reflect the project documentation at the time of its 2026-10-04 review. Defaults and configuration labels can change between revisions, so check the repository’s current instructions for the version you deploy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.