4 ms·
Here's my ruleset https://gist.github.com/eugene1g/ad3ff9783396e2cf35354689cc6473e1 https://gist.github.com/eugene1g/ad3ff9783396e2cf35354689cc6... My goal is
by e1g 8mo ago
Here's my ruleset https://gist.github.com/eugene1g/ad3ff9783396e2cf35354689cc6473e1 https://gist.github.com/eugene1g/ad3ff9783396e2cf35354689cc6...
My goal is to prevent Claude from blowing up my computer by erasing things it shouldn't touch. So the philosophy of my sanboxing is "You get write access to $allowlist, and read access to everything except for $blocklist".
I'm not concerned about data exfiltration, as implementing it well in a dev tool is too difficult, so my rules are limited to blocking highly sensitive folders by name.
- icedchai 8mo agoThat's neat. I'm going to base my ruleset off of yours. I've been messing around with claude more and more lately and I need to do something.
- AdieuToLogic 8mo ago> Here's my ruleset ... Thank you for sharing a non-trivial working example of a sandbox-exec configuration. Having an exemplar such as what you have kindly shared is hugely beneficial for those of us looking to see what can be done with a tool such as this.
- e1g 8mo agoThank you - you inspired me to open-source this work properly -> https://eugene1g.github.io/agent-safehouse/ https://eugene1g.github.io/agent-safehouse/
- AdieuToLogic 8mo ago> Thank you - you inspired me to open-source this work properly It is both myself and the OSS community which thank you. Great things are done by a series of small things brought together.[0] 0 - https://www.brainyquote.com/quotes/vincent_van_gogh_120866 https://www.brainyquote.com/quotes/vincent_van_gogh_120866