Feature request: Allow denylisting specific files/paths in sandbox mode (per-run “deny access” policy)

Resolved 💬 1 comment Opened Jan 11, 2026 by AaronMax1 Closed Jan 11, 2026

What feature would you like to see?

In sandbox mode, I’d like the ability to explicitly mark certain files or paths as non-accessible (denylist), even if the sandbox otherwise has access to the workspace filesystem. This is useful for preventing accidental reads of secrets, credentials, private datasets, or unrelated repos during runs.

Additional information

_No response_

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗