Continue.dev
noneopen sourceide-extensionRuns local commands with your full privileges, gated only by approval prompts and permission lists.
documentedContinue CLI tool permissions docs ↗
No OS-level isolation. This agent runs commands with your full user privileges. Its guardrails (approval prompts, allowlists) live inside your trust boundary, wrap it in a boundary you control.
Continue.dev runs local commands with your full user privileges, gated only by approval prompts and allow/ask/exclude permission lists, with no local OS sandbox. Its 'cloud agents' are just cn running headless on your own CI/infra, so isolation is whatever your runner provides, there is no hosted sandbox.