Sandbox

Sandboxing helps reduce risk when executing tools (especially exec) or handling untrusted content.

Recommended approach

  • start with the minimum privileges needed
  • separate “risky” workflows into isolated environments

See also: