Execution Isolation
Per-attempt boundaries for processes, workspaces, secrets, browser profiles, network access and artifacts.
Separate each attempt
Each task attempt gets its own workspace. Coding work can use isolated Git worktrees, but a worktree alone is not a security sandbox and writable Git metadata should not be shared casually.
Runtime boundary
The architecture baseline proposes rootless containers, a non-root UID, read-only base filesystem, temporary secret mounts, cgroup CPU/RAM/PID limits and seccomp/AppArmor where available. A container boundary needs host/kernel hardening and does not automatically defend against every malicious workload.
Network and secret policy
Egress is deny-by-default with allowlisted destinations; metadata endpoints and private address ranges are blocked unless approved. Secret references are scoped to project, task and tool, delivered with short TTL and redacted before logs. Workers cannot enumerate unrelated secrets.
Browser isolation
Each browser attempt needs a distinct profile directory, cookie jar, debug port and process group. The upstream browser harness can use an existing Chrome profile, so production use requires the ANDIP adapter to provide isolated profiles, policy checks and independent verification first.
Risk boundaries
Logical separation helps prevent accidental cross-task mixing but is not the same as a hardened security boundary. Untrusted public code, adversarial tenants, microVM isolation and hard multi-tenancy are not claimed as available capabilities.