Claude Code run out of disk space in vibe VM, went ahead and deleted OpenAI Codex. War of the Machines
@gosha @vladh @nikitonsky From what I understand, the process of restricting access here is basically looking for path patterns in tool calls. Like, if it wants to grep something in ../../.., or if it wants to redirect stdout to /tmp/, or the like.
The LLM just needs to be a bit creative and write itself a python script that will do the same thing, and then it gets full access with no questions asked, because the "security" of these things is that stupid.
Never run this out of a sandbox.
The 3DO game āThe Hordeā (1994) would delete any other gamesā save data it found on the console to make more room for its own save data. It did this intentionally and apparently the developers thought this was okay.