A sandbox story that feels more real than most “AI safety” pitches
What caught my attention is that this isn’t trying to sell a grand theory of safe agents. It’s much narrower: if an agent, MCP tool, or plugin is going to run code, what can that code actually touch? That’s the right question. A lot of “permission” systems stop at the door and then act surprised when the guest wanders through the house. I’m mildly skeptical of the clean 8/8 versus 0/8 framing, though. It’s a nice demo, and probably a useful one, but these attack matrices have a way of looking de
papoo.work