Aider
noneopen sourcecliNo OS-level isolation at all, it runs with your full privileges, gated only by approval prompts.
documentedAider CLI options reference docs ↗
No OS-level isolation. This agent runs commands with your full user privileges. Its guardrails (approval prompts, allowlists) live inside your trust boundary, wrap it in a boundary you control.
Aider runs with your full user privileges and has no OS-level sandbox; its only guardrails, git auto-commit/undo and confirm-before-run (/run, /test), live inside your trust boundary, gated by approval prompts. It ships an official Docker image, but that is user-driven containment you opt into, not a built-in sandbox.