Deliberately exposed and out of scope#
Paths below are inside the container. The host launcher mounts the project,
shared agent state, Git identity and explicitly requested paths. --peers
also makes sibling checkouts readable to agents. See
container mounts.
Deliberately exposed#
r means read-only; rw means read-write. These paths are restored after the
home and runtime masks described in Architecture.
Path or interface |
Mode |
Purpose and limits |
|---|---|---|
Workspace |
rw |
Defaults to the agent’s launch directory. |
|
r |
Launch policy outside the writable workspace |
|
r |
Git identity, HTTPS rewrites and forge credential helpers |
|
r |
Outer system config remains readable; ordinary Git calls ignore it through |
|
rw |
Claude’s login, settings, hooks and memory; Claude sessions only |
|
rw |
Codex’s state; Codex sessions only. Its |
|
rw |
Pi’s state, including all configured provider credentials; Pi sessions only |
|
rw |
Shared across agents and projects using the same terminal config; any agent can alter skills another later loads |
|
rw |
Claude’s temp root ( |
|
rw |
Tool caches, if present |
|
rw |
Forge tokens; omitted with |
|
rw |
Tool data and plugins. |
|
rw |
Individual tool binaries; the rest of the directory stays temporary |
|
r |
Agent binaries, the sandbox’s Python interpreter and venv, and shipped skills. Claude is also bound at |
Configured devices |
rw |
|
Network |
— |
Internet, DNS, gateway, allowed IPs and configured loopback relays; private networks otherwise blocked by default |
Agent state and shared skills persist through /user-terminal-config when
mounted. Forge tokens stay in the project container. See
configuration for overrides and
Sandbox internals for bind details.
Out of scope#
Exposure |
What to do |
|---|---|
Secrets in the workspace or readable mounts |
Keep secrets outside those paths; read-only access still permits disclosure |
Overpowered forge tokens |
Use short-lived, project-scoped tokens with only required permissions |
Credentials stored in custom locations, |
Audit tool storage and container mounts |
Internet exfiltration |
Apply an external egress policy if needed; this jail does not filter domains |
Host kernel or device-driver exploits |
Keep the host patched and grant device access only to trusted workloads |
Device resource exhaustion or device side effects |
Limit which hardware the workload can access; raw disks bypass filesystem protections |
Deliberate wrapper bypass by the operator |
Apply separate organisational controls where required |
The supported setup is a root user inside rootless Podman on Linux. Non-root devcontainers and rootful Docker are outside that setup. The threat model explains these boundaries.