SkillsHooksPromptsAgentsPersonasModelsPoliciesToolsTemplatesBundlesCategoriesStart here
← Policies
Po policyisolationboundsecuritystable

Read-only sandbox

Subprocess with read-only filesystem mount, no network, scoped to the workspace root. Used by reviewer / analyst agents.

id policy/read-only-sandboxv1.0.0by convergent-systems-key

Rule

Subprocess with read-only filesystem mount, no network, scoped to the workspace root. Used by reviewer / analyst agents.
Process
subprocess
Network
none
Filesystem
read-only
Paths
${WORKSPACE_ROOT}

Used by

Author convergent-systems-key. Source convergent-systems-co/agent-atoms (original ↗). License Apache-2.0. Re-typed from isolation-constraint by scripts/migrate-policy-tool.py.