Skip to content
Agents tracked: 284 Downloads (7d): 239M down 5.7% GitHub stars: 6.3M VS Code installs: 151M Releases (7d): 339 Agent status: 2 with issues Updated Oct 9, 2026

Coding agent safety: sandboxes, approvals and hooks

What a coding agent can do on your machine without asking depends on three things: whether commands run in a sandbox, which approval mode you are in, and whether you can block actions with your own hooks. Here is how the main agents handle each, from their own documentation (checked Oct 9, 2026).

AgentSandboxOut of the boxHooks
OpenAI Codex built-in
OS-enforced sandbox (Seatbelt on macOS, bwrap+seccomp on Linux, native on Windows): read-only, workspace-write or danger-full-access; no network and writes limited to the workspace by default.
In a git repo: edits and runs commands inside the workspace sandbox and asks for anything beyond it; read-only in untrusted folders. Yes
Cursor built-in
In Auto-review mode shell commands run in an OS sandbox where possible (Seatbelt on macOS, Landlock/Bubblewrap on Linux), with network blocked by default.
Auto-review is the recommended default: allowlisted commands run, others run sandboxed or go to a classifier or an approval prompt. Yes
OpenHands built-in
Runs the agent in a Docker sandbox by default; a process runtime runs it on the host without isolation.
The CLI asks for confirmation before actions. Yes
Google Antigravity built-in
Terminal sandbox (macOS Seatbelt, Linux namespaces) on in the Default preset on macOS and Linux; opt-in on Windows and in the CLI.
In the Default preset, workspace edits and sandboxed commands run without prompting; anything outside needs approval. Yes
Claude Code optional
OS-level Bash sandbox (Seatbelt on macOS, bubblewrap on Linux/WSL2), off by default; turn on with /sandbox or sandbox.enabled. Not available on native Windows.
Asks before file edits and before shell commands, except a built-in set of read-only commands. Yes
GitHub Copilot optional
VS Code's agent terminal sandbox is off by default (chat.agent.sandbox.enabled); Copilot CLI has an opt-in /sandbox; copilot --cloud runs in a remote isolated environment.
Asks before terminal commands except common read-only ones, and before edits to sensitive files. Yes
Gemini CLI optional
Off by default; enable with --sandbox (macOS Seatbelt, Docker/Podman, gVisor or LXC).
Asks before shell commands and file writes. Yes
Goose optional
Opt-in macOS Seatbelt sandbox for Goose Desktop (GOOSE_SANDBOX=true).
Runs freely: Autonomous mode is the default. Yes
Amp optional
No local sandbox documented; threads can run in Orbs, remote isolated machines.
Runs freely: Amp does not ask for approval before running tools. Yes
OpenCode none
No sandbox documented; a permission limits access to paths outside the working directory.
Runs freely: most permissions default to allow (paths outside the project ask; .env reads are denied). Yes
Cline none
No sandbox documented.
Asks before file edits and commands unless that Auto Approve category is on. Yes
Kiro none
No local sandbox documented; Kiro Web runs each task in an isolated cloud sandbox.
Autopilot edits files without per-step approval; shell commands ask, except allowed read-only commands. Yes
Aider none
No sandbox documented.
Edits files directly and commits each change to git; offers to run the shell commands it suggests. Not documented

built-in: commands run in an OS sandbox by default · optional: a sandbox you can turn on · none: no sandbox documented, so the agent runs with your permissions. Approval modes and sources are on each agent's page.

A safe default setup

  • Keep approvals on for shell commands until you have seen how the agent behaves in your project; allow-list the read-only commands you run often.
  • Turn on the sandbox where the agent has one, and keep network access off unless a task needs it.
  • Avoid "skip all permissions" or "yolo" modes outside a disposable container or VM.
  • Use a pre-tool hook to block what must never happen (deleting outside the repo, pushing to main, touching secrets).

When it goes wrong anyway: agents gone wrong.