Files
DocsGPT/.github
Alex 95c19f0fe7 Document sandboxed code execution in the threat model
Add code execution as an attack surface and an isolation threat: untrusted
LLM-authored code runs in the sandbox, and the self-hosted Jupyter runner is a
single trust domain (shared container/uid). Record the mitigations (approval
gating, state passed as data not code, scrubbed kernel secrets, 0700 workspaces,
network-layer egress) and that per-tenant isolation means the Daytona
per-session-VM backend or running the runner under gVisor.
2026-06-25 09:47:14 +01:00
..
2023-10-03 15:14:44 +01:00
2026-04-12 12:15:59 +01:00
2025-01-09 18:16:25 +00:00
2024-10-21 16:23:46 +01:00
2024-11-03 21:22:34 +00:00