SandboxAgent manages a workspace; CloudSandbox is the port used by remote adapters.
V4 rejects the unimplemented
docker selector. Local execution runs with the host user’s privileges; a temporary directory is not OS isolation.
Workspace or agent tools?
Use SandboxAgent when application code explicitly manages a workspace and callsrun, shell, readFile, and writeFile. Use sandbox toolkits when a model should call those operations through tools. Tool approval and execution policy still belong in the Agent or harness that exposes them.
A workspace review harness can read selected source files without enabling code execution at all.