Read-only sandbox
Subprocess with read-only filesystem mount, no network, scoped to the workspace root. Used by reviewer / analyst agents.
id policy/read-only-sandboxv1.0.0by convergent-systems-key
Rule
Subprocess with read-only filesystem mount, no network, scoped to the workspace root. Used by reviewer / analyst agents.
- Process
subprocess- Network
none- Filesystem
read-only- Paths
${WORKSPACE_ROOT}
Used by
- agent/code-reviewer — Code Reviewer
- agent/safe-by-default — Safe-by-Default Agent Template
Author convergent-systems-key. Source convergent-systems-co/agent-atoms (original ↗). License Apache-2.0. Re-typed from isolation-constraint by scripts/migrate-policy-tool.py.