Skip to content

安全沙箱

Commander's sandbox system provides secure execution isolation for all operations, with formal resource allocation via Petri net scheduling. Policies control what operations are permitted:

本文说明 安全沙箱 在 Commander 中的职责、使用方式与相关模块。命令与代码路径与产品保持一致。

bash
sandbox/
├── execPolicy.ts Execution policy definitions
├── approval.ts Approval workflow for sensitive operations
├── profiles.ts Security profiles (READ_ONLY, WORKSPACE_WRITE, FULL_ACCESS, HARDENED)
├── platforms.ts Platform-specific sandbox configurations
├── manager.ts Sandbox lifecycle management
├── executionRouter.ts Route executions to appropriate backends
├── lane.ts Execution lane management

要点

  • 与英文源文档语义对齐;API 与 CLI 以 monorepo 为准
  • 需要可运行示例时,优先使用 快速开始 中的 cliEntry.ts 路径
  • 指标口径:25 提供商 · 5 拓扑 · 18 工具 · 6700+ 测试

相关

MIT 许可 — 为多代理编排而生。