Goal
Spike Docker-based sandboxing for tool execution (especially run_shell), as called out on the roadmap / trust model.
Context
Today run_shell runs unsandboxed as the server user. A Docker (or similar) sandbox is the intended path to confine shell/file tools without changing the actor/tool API.
Acceptance criteria
Labels
help-wanted, enhancement
Goal
Spike Docker-based sandboxing for tool execution (especially
run_shell), as called out on the roadmap / trust model.Context
Today
run_shellruns unsandboxed as the server user. A Docker (or similar) sandbox is the intended path to confine shell/file tools without changing the actor/tool API.Acceptance criteria
Labels
help-wanted,enhancement