SkillsHooksPromptsAgentsPersonasModelsPoliciesToolsTemplatesBundlesCategoriesStart here
← Policies
Po policyisolationboundgovernancestable

Seccomp restricted

Subprocess with seccomp filter — only whitelisted syscalls allowed. No network; scoped filesystem.

id policy/seccomp-restrictedv1.0.0by convergent-systems-key

Rule

Subprocess with seccomp filter — only whitelisted syscalls allowed. No network; scoped filesystem.
Process
subprocess
Network
none
Filesystem
scoped
Paths
${WORKSPACE_ROOT}
Author convergent-systems-key. Source convergent-systems-co/agent-atoms (original ↗). License Apache-2.0. Re-typed from isolation-constraint by scripts/migrate-policy-tool.py.