• utopiah@lemmy.ml
    link
    fedilink
    arrow-up
    3
    ·
    3 hours ago

    Well there are guardrails from what I understood, including :

    • executing commands (off by default)
    • executing commands without user confirmation (off by default)

    which are IMHO reasonable but if the person this happened to is right, there is no filesystem sandbox, e.g. limited solely to the project repository.