Inspiration
Messy folders turn downloads, reports and notes into repetitive sorting work. AI can help decide where files belong, but a recommendation should not become unrestricted permission to change a computer. PathWarden brings a governed cleanup agent to everyday desktop users who want useful assistance while retaining control of their files.
What it does
Select a folder, request a cleanup proposal, and review every proposed move with its source, destination, reason and confidence. Denying a proposal records the decision without moving files. Approving it triggers fresh checks and bounded execution, followed by a local activity receipt. Undo derives exact reverse moves from the completed receipt and requires a separate review and approval. An optional local monitor can prepare new decisions when a folder changes; it cannot approve or execute cleanup.
How we built it
An Electron desktop shell connects to a TypeScript governance runtime. A Strands agent uses Amazon Bedrock for inference and a read-only metadata tool bound to the selected folder. The model receives filenames, extensions, sizes and modification times, not file contents or absolute local paths. Immediate subdirectory names are shared only when the user enables folder context. The agent has no filesystem mutation tools and cannot expand its inspection scope.
PathWarden treats model output as untrusted input. It validates suggestions before presenting an actionable plan, then revalidates policy, the reviewed plan, source identities and destination state before execution. A short-lived, single-use permission token binds authority to the approved operation. The governance kernel validates authority; PathWarden's executor performs permitted moves and records the outcome.
Challenges and lessons
Files can change after review, destinations can become occupied, and an operation can fail partway through. PathWarden refuses unsafe operations and distinguishes proven completion from partial or uncertain outcomes. Recovery uses journal-proven moves and requires another approval. The core lesson is that AI reasoning and execution authority can be separated in both code and the interface.
What the demo shows
The 3:28 video demonstrates proposal review, denial without changes, approved cleanup, activity receipts and independently approved restore. Its completion evidence consists of in-app results and receipts. Monitoring is an implemented additional capability, not a demonstrated trigger in this recording.
Existing work disclosure
This project incorporates PathWarden's pre-existing governance, task, filesystem and audit foundation. Commit e1e49ce identifies the documented pre-hackathon baseline. The hackathon work focuses on the Strands/Bedrock cleanup workflow, privacy-bounded planning, conversion of suggestions into reviewed plans, cleanup receipts and recovery integration, optional decision-only monitoring, and the desktop workflow shown here. The repository includes a detailed pre-existing-code disclosure.
What's next
Improve onboarding and desktop packaging, demonstrate more monitoring and recovery cases, and refine policy administration while preserving the proposal, approval and execution boundary. This submission runs locally and does not claim an AgentCore deployment or hosted execution service.
Run it
The public repository includes the source, Apache-2.0 license, architecture diagram and judge quickstart. Use your own configured AWS access for Bedrock-backed proposals and a disposable folder for the cleanup demonstration.
Built With
- amazon-bedrock
- electron
- strands-agents
- typescript
Log in or sign up for Devpost to join the conversation.