Pages
Policy Config — Sandbox Required
Source: c65 policy-definitions.md P7 — level-select shape
‹ Policy Catalog
Sandbox Required
Agent code execution is confined to a sandbox at or above the required level — --yolo runs are the canonical violation.
Action & Autonomy
medium
P7Satisfies
OWASP LLM
OWASP ASI
SOC 2
Underlying control— show
run: sandbox_mode contains "danger"edit as custom control →Minimum sandbox level
Ordered weakest → strongest; click a level to set the floor.
Everything below workspace-write raises a finding — 3 current runs below the floor.
Exceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| agent | infra-provisioner | Needs host-level writes — compensating control: dedicated VM | 2026-11-30 | |
Remediation shown on findings: Re-enable the sandbox; raise the run's sandbox mode to the floor.