mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-04 16:13:23 +00:00
Add code execution as an attack surface and an isolation threat: untrusted LLM-authored code runs in the sandbox, and the self-hosted Jupyter runner is a single trust domain (shared container/uid). Record the mitigations (approval gating, state passed as data not code, scrubbed kernel secrets, 0700 workspaces, network-layer egress) and that per-tenant isolation means the Daytona per-session-VM backend or running the runner under gVisor.