AID-I-001.004
Very High
Sandbox Network Egress Restrictions
The sandbox had already removed public internet access, so the entire channel lived inside the one destination still on the allowlist. Enumerate exact destinations, ports, and permitted operations for a code-execution sandbox, enforce that policy outside the sandboxed process, and give the container a read-only package path rather than a service whose write API it never needed.