Workspace confinement
Restricting an autonomous agent's filesystem access to a single explicitly-allowed directory so it cannot read or write files elsewhere on the host.
grounded in: CLAUDE.md operating rule 'Work ONLY inside /home/raghu/harness. Never touch files elsewhere', reinforced by the trend 'Grok CLI: an AI coding CLI caught uploading a user's entire home directory to clo
Connected concepts
Agent sandboxing, Lethal Trifecta, Data exfiltration, Capability-Based Security, Terminal-native coding agent
Explore it live in the knowledge graph →