Your sandbox guards what the agent does. Not what it's told to believe.
There's a comforting story about agent safety that goes: turn on the sandbox, deny the scary commands, and now your coding agent can't hurt you. Half of that story is true. The half it leaves out is t
raplsworks.hashnode.dev5 min read