Tested in CI·environment:LabPersonal labboundedcode-sandbox-hardening
Claim
The container runner always builds engine arguments with no network, all capabilities dropped, no-new-privileges, a non-root user, read-only mounts where requested and tmpfs masks over secret paths, and refuses sensitive host mounts such as the home directory, ~/.ssh and the Docker socket.
Status
tested
An automated test in CI asserts the claimed behaviour, including a failure case where relevant, and passes at the verified commit.
An agent that follows injected instructions cannot weaken verification — a rewritten verification config is ignored because configuration is read from the base commit and the path is protected — and a host secret behind a planted symlink never reaches a context pack.
Security·boundedcode v0.1.0-alpha.3·4 test files, 8 artifactsEvidence →