The panel is split by nearly four points on whether the lack of a sandbox is a feature or a fatal flaw.
Reasoning and trade-offs · AI analysis
The disagreement is between El Hacker, who sees a powerful, self-hosted tool to be owned and managed, and the rest of the panel, who see a security liability. La Jefa and El Crítico correctly identify the risk of running unsandboxed agents with terminal access on company hardware. El Hacker is equally correct that for an individual developer who understands the permissions model, this is a reasonable trade-off for total control and a free, open-source license.
El Hacker's reading wins for the solo developer who is willing to manage the execution risk themselves. For any team or organization, La Jefa's concerns about support and security are paramount, and she is right to flag it as a non-starter. Her ruling stands for any multi-user environment. The tool is for personal experimentation, not for production workflows against shared assets. Trial only, with the exit criterion being the first instance of an agent performing an unexpected, destructive action on the local filesystem.