Bonsai Demo explained: local inference with a fork-specific model
Bonsai safety: downloaded weights, tool calls and exposed servers
Review the provenance and permissions of every optional layer.
What you will learn
- Verify artifacts separately
- Treat the model server as an execution boundary
- Handle prompts and logs deliberately
Before you start
- A target machine with measured memory and disk
- Permission to inspect downloaded model and binary files
Capture the exact artifacts and one correctness failure before claiming a useful deployment.
Key takeaways
- Repository license does not settle every artifact license.
- Tools change the model’s effective permissions.
- Local inference can still have network-connected extras.
Verify artifacts separately
The repository license applies to demo code; model weights and downloaded binaries are separate artifacts. Check each model card and runtime license, pin revisions and hashes, and review what setup.sh retrieves.
Do not assume that a GitHub repository marked Apache-2.0 grants every right to redistribute hosted weights or bundle a fork binary. Keep notices and download provenance with the deployment record.
Treat the model server as an execution boundary
A loopback text endpoint is easier to contain than a server exposed on a shared network. The README describes tool calls, MCP and optional code interpreter; enabling these expands what model-driven requests can cause.
Limit tool permissions, require confirmation for destructive actions and use synthetic inputs during initial testing. An apparently local model can still contact the network through its tools or UI integrations.
Handle prompts and logs deliberately
Prompts, screenshots for vision, model responses and tool outputs can contain private data. Decide what is logged, retained and shared before adding the optional UI or agent demo.
This is a review of documented boundaries, not a security certification. We did not execute the model, binary or tools, and did not audit every downloaded dependency.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Inventory code, weights and binary licenses separately.
- 2
Keep the first server on loopback without tools.
- 3
Approve and log every newly enabled tool capability.
Copy-ready example
artifact_review:
demo_code: license-and-commit
model_weights: model-card-and-hash
fork_binary: release-and-hash
server_host: 127.0.0.1
tools: disabled-until-reviewedFrequently asked questions
Is the demo’s Apache license enough for weights?
Check the separate model card and artifact terms before redistribution.
Does localhost make code interpreter safe?
It reduces network exposure but does not remove local execution risk.
Sources
- Bonsai Demo / README.mdSource checked 2026-09-29
- Bonsai Demo / setup.shSource checked 2026-09-29
- Bonsai Demo / scripts/agent/run_agent_demo.shSource checked 2026-09-29