Loading…
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.
Our verdict: worth borrowing ideas from
First-party filesystem/network sandboxing for agent shell commands. GRAFT into the Bash hooks rather than adopting wholesale.
Filed under security in our directory.