Sandbox
Also: 沙箱 · 沙盒 · 權限模式 · permission mode
The fence around what an AI may touch: which folders are writable, whether it has network access, and whether it must ask you each time.
When you will meet it
An AI that can run commands can delete files, spend your money, and exfiltrate data. The sandbox is your only preventive control; reading logs afterwards is too late.
An analogy
Giving a child a playpen rather than keys to the whole house. Anything can happen inside; nothing gets out.
Minimal example
常見的幾種寬緊程度(由緊到鬆):
唯讀 可以看,不能改
workspace-write 只能改專案目錄內,碰不到外面、也不能上網
逐次詢問 每個敏感動作都要你按同意
完全放開 沒有圍欄(除非在一次性容器裡,否則不要)Principle: use the tightest setting that still gets the job done. Loosening is easy; tightening back is hard.
What people get wrong
- Opening everything up front to save friction. When something breaks you discover there was no fence, and it is too late to add one.
- Assuming a sandbox stops prompt injection. It limits what CAN be done, not what the agent can be persuaded to WANT to do. You need both.