Skip to content
Read the original: Zed Blog· Cameron Mcloughlin·PublishedPickAI score65

Zed Enables OS-Level Sandboxing by Default for Its Agent Panel

Sandboxing

AISummary

Zed's agent panel now sandboxes its terminal and fetch tools by default, starting in release 1.14, and the restrictions are enforced by the operating system rather than by agent instructions. By default the sandbox blocks writes outside project directories, writes to .git, and network requests, and agents can request temporary escalation with a stated reason. The post also notes that sandboxing covers only those tools and does not protect against other tools, external programs, or the regular built-in terminal.

AIWhy it matters

The post explains how OS-enforced sandboxing limits agent terminal and fetch access, and why fine-grained command rules fall short of it.

Read the original zed.dev

Source: Zed Blog · zed.dev