Comment by jeremyjh
1 hour ago
That is not what sandboxing solves. A good sandbox would inject credentials into provider API calls so that the model never sees credentials, but the provider is still going to see the transcript. Sandboxes do not require or imply that there is a local model. Sandboxes limit what the agent can access on the host machine as well as the network and public internet.
>Sandboxes limit what the agent can access on the host machine as well as the network and public internet.
this is exactly what I meant. I am presuming the danger is AI reacting to personal notes that it reads on your computer, like a diary, and you should not allow the tools to have access to those documents.