The outcome

Create a repeatable local environment that limits the impact of mistakes or hostile repository content.

Step by step

A workflow you can repeat.

  1. 01

    Choose the current Docker-based setup, inventory host risks, and define which project files, services, and model provider the agent truly needs.

  2. 02

    Use a dedicated repository checkout and minimal read-write mount, keeping unrelated directories, sockets, credential stores, and production data outside the sandbox.

  3. 03

    Provide short-lived least-privilege credentials through approved configuration and restrict outbound access or tools where your environment permits.

  4. 04

    Enable action confirmations and security analysis, then test harmless, destructive, unknown-risk, network, and secret-access scenarios before real work.

  5. 05

    Document setup, image and dependency versions, logs, cleanup, credential rotation, and an incident procedure; review the boundary after every upgrade.

Working standard

What good use looks like.

  • Prefer Docker isolation to direct host execution.
  • Use short-lived least-privilege credentials.
  • Test rejection and cleanup paths.

Official references

Check the current product documentation.