Skip to content

Document SandboxPathPolicy examples and forbidden write targets #2

@wxici

Description

@wxici

Maintainer backlog item

WebMuse has sandbox path policy foundations, but public documentation needs clearer examples of allowed and forbidden write targets.

Why this matters

The project exists to make AI-assisted construction safer. Reviewers and contributors should understand what paths are considered unsafe.

Proposed scope

Document examples for:

  • allowed project workspace paths
  • Codex write-root boundaries
  • forbidden system directories
  • credential directories
  • installation directories
  • source roots outside the selected project
  • Windows reparse point checks

Acceptance criteria

  • Add examples to docs/ARCHITECTURE.md or a dedicated sandbox document.
  • Do not expose local private paths.
  • Keep examples generic and safe.

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions