安全沙箱
Commander's sandbox system provides secure execution isolation for all operations, with formal resource allocation via Petri net scheduling. Policies control what operations are permitted:
本文说明 安全沙箱 在 Commander 中的职责、使用方式与相关模块。命令与代码路径与产品保持一致。
bash
sandbox/
├── execPolicy.ts ← Execution policy definitions
├── approval.ts ← Approval workflow for sensitive operations
├── profiles.ts ← Security profiles (READ_ONLY, WORKSPACE_WRITE, FULL_ACCESS, HARDENED)
├── platforms.ts ← Platform-specific sandbox configurations
├── manager.ts ← Sandbox lifecycle management
├── executionRouter.ts ← Route executions to appropriate backends
├── lane.ts ← Execution lane management要点
- 与英文源文档语义对齐;API 与 CLI 以 monorepo 为准
- 需要可运行示例时,优先使用 快速开始 中的
cliEntry.ts路径 - 指标口径:25 提供商 · 5 拓扑 · 18 工具 · 6700+ 测试