Modes: off |
non-main |
all. |
Scope: session |
agent |
shared (containers). |
workspaceAccess: none |
ro |
rw (sandbox workspace vs agent workspace). |
openclaw-sandbox:bookworm-slim; build with scripts/sandbox-setup.sh.See: Sandboxing
tools.allow / tools.deny; per-agent agents.list[].tools; sandbox tool policy (tools.sandbox.tools). Deny wins.