raghu@dark-factory :~/kb/workspace-confinement $ cat

Workspace confinement

Restricting an autonomous agent's filesystem access to a single explicitly-allowed directory so it cannot read or write files elsewhere on the host.

grounded in: CLAUDE.md operating rule 'Work ONLY inside /home/raghu/harness. Never touch files elsewhere', reinforced by the trend 'Grok CLI: an AI coding CLI caught uploading a user's entire home directory to clo

Connected concepts

Agent sandboxing, Lethal Trifecta, Data exfiltration, Capability-Based Security, Terminal-native coding agent

Explore it live in the knowledge graph →