1 Filesystem Capability
jfabian edited this page 2026-08-13 11:15:47 -03:00

Filesystem Access: Security by Design

Direct System Access Is Prohibited

One of the most critical design decisions in VOX is the prohibition of direct system access.

  • The Problem: Traditional agents often run with the same permissions as the user, creating a massive attack surface for prompt injection or supply-chain attacks.
  • The VOX Solution: Direct filesystem calls are blocked at the architecture level. No capability exposes raw host filesystem access.
  • Enforcement: Agents persist files exclusively through their own VOXAgentStore instance, which acts as a sandboxed proxy:
    1. Every agent is restricted to its own asset sandbox at agents/<name>/assets/.
    2. Every file is stored under a UUID name (collision and traversal safe).
    3. Every I/O operation is recorded in the asset_index ledger for auditing.
    4. get_safe_path() / retrieve_file() enforce sandbox confinement and reject traversal attempts with PermissionError.
    5. Content is deduplicated by SHA-256 checksum before physical storage.

Note: By decoupling the intent (Agent) from the action (sandboxed store), we ensure that even a compromised agent cannot perform lateral movement within the host system.