Coding agent safety: sandboxes, approvals and hooks
What a coding agent can do on your machine without asking depends on three things: whether commands run in a sandbox, which approval mode you are in, and whether you can block actions with your own hooks. Here is how the main agents handle each, from their own documentation (checked Oct 9, 2026).
| Agent | Sandbox | Out of the box | Hooks |
|---|---|---|---|
| OpenAI Codex | built-in OS-enforced sandbox (Seatbelt on macOS, bwrap+seccomp on Linux, native on Windows): read-only, workspace-write or danger-full-access; no network and writes limited to the workspace by default. |
In a git repo: edits and runs commands inside the workspace sandbox and asks for anything beyond it; read-only in untrusted folders. | Yes |
| Cursor | built-in In Auto-review mode shell commands run in an OS sandbox where possible (Seatbelt on macOS, Landlock/Bubblewrap on Linux), with network blocked by default. |
Auto-review is the recommended default: allowlisted commands run, others run sandboxed or go to a classifier or an approval prompt. | Yes |
| OpenHands | built-in Runs the agent in a Docker sandbox by default; a process runtime runs it on the host without isolation. |
The CLI asks for confirmation before actions. | Yes |
| Google Antigravity | built-in Terminal sandbox (macOS Seatbelt, Linux namespaces) on in the Default preset on macOS and Linux; opt-in on Windows and in the CLI. |
In the Default preset, workspace edits and sandboxed commands run without prompting; anything outside needs approval. | Yes |
| Claude Code | optional OS-level Bash sandbox (Seatbelt on macOS, bubblewrap on Linux/WSL2), off by default; turn on with /sandbox or sandbox.enabled. Not available on native Windows. |
Asks before file edits and before shell commands, except a built-in set of read-only commands. | Yes |
| GitHub Copilot | optional VS Code's agent terminal sandbox is off by default (chat.agent.sandbox.enabled); Copilot CLI has an opt-in /sandbox; copilot --cloud runs in a remote isolated environment. |
Asks before terminal commands except common read-only ones, and before edits to sensitive files. | Yes |
| Gemini CLI | optional Off by default; enable with --sandbox (macOS Seatbelt, Docker/Podman, gVisor or LXC). |
Asks before shell commands and file writes. | Yes |
| Goose | optional Opt-in macOS Seatbelt sandbox for Goose Desktop (GOOSE_SANDBOX=true). |
Runs freely: Autonomous mode is the default. | Yes |
| Amp | optional No local sandbox documented; threads can run in Orbs, remote isolated machines. |
Runs freely: Amp does not ask for approval before running tools. | Yes |
| OpenCode | none No sandbox documented; a permission limits access to paths outside the working directory. |
Runs freely: most permissions default to allow (paths outside the project ask; .env reads are denied). | Yes |
| Cline | none No sandbox documented. |
Asks before file edits and commands unless that Auto Approve category is on. | Yes |
| Kiro | none No local sandbox documented; Kiro Web runs each task in an isolated cloud sandbox. |
Autopilot edits files without per-step approval; shell commands ask, except allowed read-only commands. | Yes |
| Aider | none No sandbox documented. |
Edits files directly and commits each change to git; offers to run the shell commands it suggests. | Not documented |
built-in: commands run in an OS sandbox by default · optional: a sandbox you can turn on · none: no sandbox documented, so the agent runs with your permissions. Approval modes and sources are on each agent's page.
A safe default setup
- Keep approvals on for shell commands until you have seen how the agent behaves in your project; allow-list the read-only commands you run often.
- Turn on the sandbox where the agent has one, and keep network access off unless a task needs it.
- Avoid "skip all permissions" or "yolo" modes outside a disposable container or VM.
- Use a pre-tool hook to block what must never happen (deleting outside the repo, pushing to main, touching secrets).
When it goes wrong anyway: agents gone wrong.