basePath directory, preventing traversal attacks.
Shortcut on Agent: workspace: { path: "./data", mode: "read" } enables read-only workspace tools. Choose mode: "write" explicitly for writes. Path checks are not an OS sandbox. That is host disk. Durable notes for the agent’s future self are a different switch: filesystem: true (agent_fs_* tools). See Harness.
Quick Start
Config
string
Root directory for file access. All paths are resolved relative to this. Prevents directory traversal.
boolean
default:"false"
Enable the
fs_write_file tool. Disabled by default for safety.