Your sandbox says what the agent could do. What did it do?
The agent sandboxes I've used tell you the rules before the run. This directory is writable. That one's read-only. No network except the proxy. Some of them sign it, and that's good. Then the agent runs for forty minutes, exits, and the sandbox has nothing more to say. The question you actually have at that point is simple. What did it touch? You can answer it by hand. git status if the workspace…
The agent sandbox provides a boundary statement outlining the rules before the run, while the actual changes inside the sandbox are observed as a change statement. The sandbox is read-only, with no network access except through a proxy. After running for forty minutes, the sandbox exits and provides no further information. To determine what the agent touched, one must compare snapshots taken before and after the run.
This comparison is straightforward, but the challenge lies in accurately identifying what the agent did not see. A naive diff might overlook a directory becoming unreadable or a bind mount pointing elsewhere. Pipelock addresses these issues by creating a manifest of the granted workspace, including path kind, size, modification time, and SHA256 digest.
The pre-launch posture capsule is signed by a key that only the operator holds, ensuring the signature's integrity. The change record is incomplete if anything was excluded or the granted root disappeared, and verification fails if the signatures do not match. This approach provides honest evidence of what the agent did without allowing it to edit the record.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.