Docs · Sandbox & Permissions

Sandbox & Permissions.

Confinement that survives yolo.

Direct answer

Every tool call resolves through one declarative policy covering reads, writes, execution, network and environment. Approval decides whether an action is attempted; the sandbox decides whether it is possible. Learn the three profiles before your first unattended run, and remember that --yolo never widens confinement.

Sandbox & Permissions

Profiles

01project · defaultRead and write inside the project root. The right profile for a normal repository and the safest starting point.
02computerRead your home directory and work root, write only to the work root, state and temp. For tasks that need reference material outside the repo.
03strictNetwork denied, shell execution refused until a kernel backend is active. Use for untrusted prompts or regulated code.

Sandbox & Permissions

Rules of the boundary

01Approval ≠ permission--yolo skips prompts but a policy-violating action is still refused and reported. Denials surface; they are not retried into a different shape.
02All exec paths share one checkrun_command, run_script and monitor all pass the same shell policy, there is no unfenced execution route.
03Sanitized environmentProvider keys, tokens and secrets are stripped from child environments unless a variable is explicitly allowed through.
04Kernel enforcement is opt-inmacOS Seatbelt and Linux Landlock are available but enabled per config once you want OS-level guarantees; until then the tool-layer policy is the boundary, and unsupported platforms refuse rather than run unconfined.

Questions

Asked About Sandbox & Permissions.

Q

Why did a command get refused under --yolo?

Because approval and confinement are separate: the call was approved to run, but the policy determined it was out of scope. Read the refusal reason, it names the violated or missing capability.

Q

Can I allow one directory outside the project?

Yes, through policy scopes in config rather than by disabling the sandbox. Prefer the narrowest addition that unblocks the task, and remove it when done.

Q

Does the sandbox cover network too?

Yes. Network access is part of the policy; strict denies it, and the computer/project profiles gate the tools that reach out (fetch and search) through the same policy object.

Run Agents That Fit On Your Laptop.

25.6 MB median RSS. 25 agents ran in parallel on a Core 2 Duo with 4 GB RAM. Hundreds on your machine. Zero cloud required on the Ollama path.

Requires Rust/cargo to build from source. Linux and macOS today, Windows not yet supported. Pre-1.0, public beta. Pricing TBD.