Page:
Filesystem Capability
Pages
Agent Lifecycle
Architecture Overview
Building Blocks
Capabilities Reference
Capability Contract
Capability Spec
Comm Gateway
Core Ontology
Creating an Agent
Filesystem Capability
Hierarchical Messaging Contract
Home
Messaging Contract
Orchestrator and Control Plane
Security Architecture
Segmented Persistence Forensic Traceability
VOXAgent
VOXApiServer
VOXCapability
VOXMessage
VOXOrchestrator
VOXRole
Versioning
War Room
WhatsApp Setup
No results
1
Filesystem Capability
jfabian edited this page 2026-08-13 11:15:47 -03:00
Table of Contents
Filesystem Access: Security by Design
Direct System Access Is Prohibited
One of the most critical design decisions in VOX is the prohibition of direct system access.
- The Problem: Traditional agents often run with the same permissions as the user, creating a massive attack surface for prompt injection or supply-chain attacks.
- The VOX Solution: Direct filesystem calls are blocked at the architecture level. No capability exposes raw host filesystem access.
- Enforcement: Agents persist files exclusively through their own
VOXAgentStoreinstance, which acts as a sandboxed proxy:- Every agent is restricted to its own asset sandbox at
agents/<name>/assets/. - Every file is stored under a UUID name (collision and traversal safe).
- Every I/O operation is recorded in the
asset_indexledger for auditing. get_safe_path()/retrieve_file()enforce sandbox confinement and reject traversal attempts withPermissionError.- Content is deduplicated by SHA-256 checksum before physical storage.
- Every agent is restricted to its own asset sandbox at
Note: By decoupling the intent (Agent) from the action (sandboxed store), we ensure that even a compromised agent cannot perform lateral movement within the host system.
Overview
- Home
- Versioning
- Architecture Overview
- Building Blocks
Agent Model
- VOXAgent
- Agent Lifecycle
- VOXRole
- Creating an Agent
Capabilities
- VOXCapability
- Capabilities Reference
- Capability Contract
- Comm Gateway
- WhatsApp Setup
Messaging
- VOXMessage
- Messaging Contract
- Hierarchical Messaging Contract
- The War Room
Orchestrator & Control Plane
- VOXOrchestrator
- Orchestrator & Control Plane
- VOXApiServer
Persistence & Forensics
- Segmented Persistence & Forensic Traceability
Security & Governance
- Security Architecture
- Core Ontology (legacy)
- Capability Specification (legacy)
Status: v0.5.4