Every tool so far was a typed JSON function, a narrow keyhole. Code execution lets the agent write and run code; computer-use lets it act on files and the network. Capability and danger arrive together. Flip the SANDBOX toggle, pick an operation, and run it: with the boundary OFF the dangerous ones do simulated damage; with it ON the same attacks are blocked while legitimate work still passes.
gVisor / Firecracker / containers). Damage shown is simulated.
ALLOWED_HOSTS is empty.
sum/len/round); command allowlist read_file/write_file only.evil.com.round(sum(orders) / len(orders), 2) → 173.33 and the legitimate write still pass.