Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Claude: can escape its sandbox (there are GitHub issues about this) and, when sandboxed, still has full read access to everything on your machine (SSH keys, API keys, files, etc.)

Codex: IIRC, only shell commands are sandboxed; the actual agent runtime is not.



Cool, thanks for explaining!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: