Amp
nonecliNo OS-level isolation, it runs with your full privileges, gated only by approval prompts.
documentedAmp Owner's Manual ↗
No OS-level isolation. This agent runs commands with your full user privileges. Its guardrails (approval prompts, allowlists) live inside your trust boundary, wrap it in a boundary you control.
Amp runs with your full user privileges and has no OS-level sandbox. Its allow/ask/reject rules engine is configuration inside your trust boundary, gated by approval prompts, a documented July 2025 self-granted 'allow all' via a wildcard, proving these rules are config, not a boundary.