@liran_tal That's exactly my point. A containerized environment isn't a sandbox either, without proper isolation. What am I missing? How's the agent in the screenshot escaping the sandbox?
@liran_tal It depends on context. Here it should be a restricted execution env; if the only guardrails are AGENTS.md instructions, then the agent isnt really escaping a sandbox.