A task sees only the env it names
Undeclared variables never reach a task, and secrets are masked in its output.

A build that reads a stray variable from your shell works on your machine and nowhere else. vx starts each task with a clean environment plus what you name.
passThrough lets a variable in, define sets one, and secret masks a value wherever it would be printed.
// config
// packages/api/vx.config.ts
import { defineProject } from '@vzn/vx/config'
export default defineProject({
tasks: {
deploy: {
exec: {
command: './deploy.sh',
env: {
passThrough: ['DEPLOY_TOKEN'],
define: { NODE_ENV: 'production' },
secret: ['DEPLOY_TOKEN'],
},
},
},
},
})More in Correct by default

Projects stay in their lane
A project’s globs never reach into another project’s files.

Damaged artifacts are misses
Every artifact is checked before it is restored; damage means a rebuild, not a wrong file.

The sandbox says what to allow
A refused write is named beside the failed task, with the line that allows it.

Numbers mean what you typed
Hex, exponents and fractions are refused, never quietly reinterpreted.

Releases you can verify
Binaries carry provenance, and vx upgrade checks every download’s SHA-256.