Tool policy reduces risk but is not an operating-system sandbox.
Path validation, symlink/junction checks and scope rules constrain built-in file operations.
Protected commands, internet, sensitive, destructive, privileged and custom actions require policy decisions.
Credential-like data is redacted from visible/persisted tool evidence; SSH secrets use VS Code SecretStorage.
Any selected remote/API model receives the prompt and context you send. Use endpoints you trust.
Approved commands execute with your OS account privileges; inspect them before allowing.