Studio: clarify that shell network commands are blocked, not allowlisted
The reworded note said the tools can reach an allowlist of public sites, but that egress is only for code execution; the terminal tool's network commands are blocked. Distinguish the two so the note is accurate for both tools.
This commit is contained in:
parent
57a73f34d5
commit
c2903da6a5
1 changed files with 5 additions and 4 deletions
|
|
@ -2956,10 +2956,11 @@ _SANDBOX_PATHS_NOTE = (
|
|||
" The working directory is an isolated scratch space that may already hold "
|
||||
"files from earlier work in this conversation or project, plus anything you "
|
||||
"create here or that is uploaded; it persists across this conversation and, "
|
||||
"for a project, across the project's threads. It can reach only a fixed "
|
||||
"allowlist of public sites (such as github.com, huggingface.co, and "
|
||||
"pypi.org), not the user's own machines, private hosts, or arbitrary "
|
||||
"addresses. A repository, folder, or file the user refers to is not present "
|
||||
"for a project, across the project's threads. Code execution can fetch from a "
|
||||
"fixed allowlist of public sites (such as github.com, huggingface.co, and "
|
||||
"pypi.org); shell network commands are blocked, and neither can reach the "
|
||||
"user's own machines, private hosts, or arbitrary addresses. A repository, "
|
||||
"folder, or file the user refers to is not present "
|
||||
"here unless it was uploaded, created here, or already part of this project, "
|
||||
"so list the working directory to see what is available rather than assuming "
|
||||
"a mentioned path exists or guessing where it lives. Read and write files "
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue