The outcome
Create a repeatable local environment that limits the impact of mistakes or hostile repository content.
Step by step
A workflow you can repeat.
- 01
Choose the current Docker-based setup, inventory host risks, and define which project files, services, and model provider the agent truly needs.
- 02
Use a dedicated repository checkout and minimal read-write mount, keeping unrelated directories, sockets, credential stores, and production data outside the sandbox.
- 03
Provide short-lived least-privilege credentials through approved configuration and restrict outbound access or tools where your environment permits.
- 04
Enable action confirmations and security analysis, then test harmless, destructive, unknown-risk, network, and secret-access scenarios before real work.
- 05
Document setup, image and dependency versions, logs, cleanup, credential rotation, and an incident procedure; review the boundary after every upgrade.
Working standard
What good use looks like.
- Prefer Docker isolation to direct host execution.
- Use short-lived least-privilege credentials.
- Test rejection and cleanup paths.
Official references