Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
“Local” tells you where a coding agent runs; it does not tell you what it can read, change, execute, or reach over the network. To judge whether an agent stays within a project, define and inspect its effective boundary: filesystem access, network access, credentials, covered processes, and how exceptions work.
What a measurable boundary includes
A boundary is the set of enforceable rules that constrain an agent and the commands or tools it can invoke. A project path, working directory, or reassuring product label is not enough. For a particular agent session, record these controls:
- Filesystem: Which paths can be read, written, or denied? Is the project mounted read-write? Are home directories, caches, or configuration folders exposed?
- Network: Is outbound access enabled? Can destinations be restricted? Can the agent reach local or private-network services?
- Credentials and environment: Which environment variables, Git credentials, API tokens, tool configurations, and caches are available?
- Processes and tools: Do terminal commands and child processes share the limits? What about built-in file tools, MCP servers, language servers, or separately launched services?
- Exceptions: Does a blocked action fail, require a narrowly scoped approval, or offer an unsandboxed retry? Who can allow that retry?
- Verification and cleanup: Can you inspect the active session’s effective policy? Which changes are disposable, and which persist in the host workspace?
The useful description is not simply “sandboxed” or “local.” It is a testable configuration, plus observed behavior for the session in question.
Why a workspace path is not an isolation boundary
A process can start in a project directory and still have access to files or services elsewhere on its host. The OpenAI Agents SDK documentation says its Unix-local backend on Linux runs commands as local host processes and adds no OS-level confinement; setting a workspace, HOME, or cwd does not restrict access the host process is permitted to have. The same documentation says the macOS backend applies filesystem restrictions but does not provide network isolation or a container-equivalent boundary. See the OpenAI Agents SDK sandbox clients documentation.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The SDK’s Unix-local client inherits the host process environment by default. Setting inherit_host_environment=False filters that inheritance, but the documentation explicitly says this does not add OS-level confinement. Filtering environment variables can reduce what a command inherits; it does not, by itself, stop the process from accessing host files or networks.
How local, sandboxed, and container execution differ
These labels can describe different enforcement layers. The comparison below uses the documented examples from the OpenAI Agents SDK, VS Code, and Docker. Their policies are product-specific, and a setting’s default should not be assumed to apply to another product or version.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Execution option | Enforcement and filesystem | Network and credentials | Exceptions, coverage, and persistence |
|---|---|---|---|
| OpenAI Agents SDK Unix-local backend | On Linux, commands run as local host processes with no OS-level confinement. On macOS, the SDK documents filesystem restrictions but not network isolation or a container-equivalent boundary. A workspace path alone does not restrict host-permitted access. | On both platforms, review the host process environment and available network access; on macOS, the SDK specifically says network isolation is not provided. Environment inheritance is on by default; disabling it filters inheritance without adding confinement. | Commands run locally. The SDK recommends Docker, hosted execution, or external isolation for untrusted commands, with permissions, mounts, credentials, and network access reviewed. |
| VS Code Agent Host sandbox | Filesystem restrictions can define read-write, read-only, and denied paths; denied paths take precedence. The documentation says filesystem and network controls are separate. | In the documentation dated 2026-10-07, outbound networking is enabled by default and local-network access is disabled by default. Developer-tool access is enabled by default and can expose tool directories, configuration, caches (including registry tokens), and shared build caches. Git and GitHub authentication can also be passed to sandboxed processes through default settings. | In that same documentation, sandboxing is off by default, custom filesystem path lists are empty, and requests to run unsandboxed are allowed by default. Approval controls and sandbox enforcement are distinct; tool coverage and settings need to be checked for the session. |
| Docker Sandboxes tutorial workflow | The agent gets a private environment with its own operating system and Docker daemon; installed tools and system changes can be discarded. The project directory is shared read-write, so the agent can modify or delete project files. | The tutorial lets the user choose a network policy. Its Balanced policy allows common development services while blocking other destinations by default. Treat the project mount as an explicit exposure even when other environment changes are disposable. | Review project edits with version control, such as git diff. The disposable environment does not make changes to the shared project directory disposable. |
What VS Code’s documented defaults mean in practice
Microsoft’s Agent Host documentation, dated 2026-10-07, is a useful example of why “sandbox enabled” is too vague. On that page, sandboxing itself is off by default. If used, outbound networking is allowed by default, local-network access is disabled by default, allowed and denied domain lists and user-configured filesystem path lists are empty by default, and requests to run unsandboxed are allowed by default. These are documented defaults for that product page, not universal properties of coding-agent sandboxes.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Filesystem and network policy are independent: a path rule does not establish which destinations a process can contact, and a network rule does not establish which files it can read. Filesystem policy supports read-write, read-only, and denied paths, with denied paths taking precedence. The same documentation warns that developer-tool grants can reveal configuration and caches, including registry tokens, and that Git or GitHub authentication may be passed through. Include those exposures when describing the boundary, not just the workspace folder.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
To inspect the effective policy for an active session, VS Code documents the /sandbox policy command. It reports whether restrictions are active and describes the effective filesystem and network policy. Checking the session is more reliable than inferring its protections from a setting name or interface mode.
What containers protect—and what they do not
Docker’s tutorial describes a local environment with its own operating system and Docker daemon. Tools installed and system changes made inside that environment can be left behind when it is discarded. That gives a different execution scope from a local host process, but the shared project directory remains consequential: it is mounted read-write, and the agent can modify or delete files there.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Keep the project under version control and inspect changes before accepting them. Docker’s tutorial uses git diff for review. A disposable container protects the host from some changes made inside its environment; it does not make a writable host-project mount disposable. See Docker’s coding-agent sandbox tutorial for the described workflow and network-policy choice.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Why approval prompts are not a substitute for enforcement
An approval prompt governs whether an action runs automatically or waits for confirmation. Sandboxing constrains what a process can access if it runs. Microsoft’s VS Code security documentation treats these as separate controls: terminal commands and their child processes may be restricted by sandboxing, while non-process tools have separate permission checks. MCP and language-server processes are sandboxed only when relevant settings apply.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The distinction matters because commands and tools may act with the user’s permissions and credentials. Risks identified in the documentation include changing files, installing software, making external API calls, altering infrastructure, and deploying. VS Code also cautions that auto-approval uses best-effort command parsing with known limitations; a prompt or automatic-approval rule is not an OS-enforced boundary. Microsoft summarizes the limit this way: “Sandboxing is an added layer. It is not a virtual machine or user-account boundary, a standalone security boundary, or a replacement for endpoint security.” Read the VS Code security documentation for its distinction between approvals, sandboxing, and other tool permissions.
A practical boundary check for an agent session
Answer these questions for the exact product, configuration, and session you plan to use. If a policy is not inspectable or a process is outside its scope, treat that as an unknown—not as evidence that access is restricted.
- Map file access. List readable, writable, and denied paths. Confirm whether the workspace is mounted read-write and whether host directories, configuration, caches, or shared build locations are also exposed.
- Check process coverage. Determine whether terminal commands and their child processes share the same restrictions. Separately check built-in file tools, MCP servers, language servers, and independently launched services.
- Check network reach. Establish whether outbound networking is on, whether destinations can be allowlisted or denied, and whether local or private-network services are reachable.
- Inventory credentials. Find out which environment variables, Git or API authentication, tool configuration, caches, and secrets the process can use. Do not assume environment filtering is filesystem or network isolation.
- Test the exception path. Learn whether a blocked operation fails, triggers an approval, or can be retried outside the boundary. Identify who can authorize that exception.
- Inspect effective policy and persistence. Use the product’s session-level policy report where available. Identify which changes survive in the host workspace and which are confined to a disposable environment.
Least privilege is difficult to infer from a task
A preprint introducing AuthBench reports 120 realistic terminal tasks and finds that frontier models can omit permissions needed by an execution chain while also granting unused or sensitive access. Its authors say increased inference-time reasoning did not resolve the mismatch. This is a finding about the tested tasks and models, not a result that establishes how every coding agent or workload behaves. The paper is available at arXiv: “Do Coding Agents Understand Least-Privilege Authorization?”.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The practical implication is to verify what the system actually enforces rather than relying on an agent’s apparent task understanding or a product label. A defensible boundary states the allowed paths, network reach, credential exposure, process coverage, and exception mechanism—and provides a way to check the active policy.

