AI Coding Agents
Claude Code
Run Claude Code with access limited to your project:OpenClaw
Run OpenClaw gateway with nono sandbox:Generic AI Agent
Checking Path Access
Why is a path blocked?
Check with capability context
Query from inside a sandbox
Check network access
Build Tools
Cargo (Rust)
npm/Node.js
Make
Network Operations
curl/wget
Git Operations
Multi-Directory Access
Separate Source and Output
Multiple Projects
Shared Dependencies
Debugging and Testing
Dry Run
Preview what access would be granted:Verbose Output
Testing Sandbox Enforcement
Shell Scripts
Running a Script
Inline Commands
Configuration Files
Read-Only Config
Multiple Config Files
Using Profiles
Built-in Profiles
Profile with Extra Permissions
Profile with Custom Workdir
Restrict Profile to Specific Domains
Real-World Scenarios
Code Review Agent
An agent that reads code and writes review comments:Documentation Generator
An agent that reads source and generates docs:Data Processing Pipeline
Cloud Agent with Credential Access
By default,~/.aws and ~/.config/gcloud are blocked by the deny_credentials group. Use --override-deny to grant targeted access: