Does --yolo widen the sandbox?
No. In Anvaya, approval and confinement are orthogonal: --yolo auto-approves but the same policy still blocks out-of-scope reads, writes, exec and network.
Glossary · Sandbox Policy
Approval and confinement are different axes.
Direct answer
A sandbox policy declares what an agent may read, write, execute and reach over the network, and is enforced independently of approval prompts. The key property: auto-approving actions (yolo mode) must not widen confinement, approval decides whether an action is attempted, the sandbox decides whether it is possible. Profiles typically range from project-scoped to whole-computer to strict-deny, with a fail-closed capability report when the OS backend cannot enforce the policy.
In Anvaya
Questions
No. In Anvaya, approval and confinement are orthogonal: --yolo auto-approves but the same policy still blocks out-of-scope reads, writes, exec and network.
Applying the policy through OS primitives (Seatbelt, Landlock) instead of only checking arguments in the tool. It is opt-in in Anvaya until the default allow-list passes a build fixture.
A refused capability, named explicitly, fail-closed. Anvaya reports which confinement is missing rather than silently running unconfined.
25.6 MB median RSS. 25 agents ran in parallel on a Core 2 Duo with 4 GB RAM. Hundreds on your machine. Zero cloud required on the Ollama path.
Requires Rust/cargo to build from source. Linux and macOS today, Windows not yet supported. Pre-1.0, public beta. Pricing TBD.