The split is over what counts as containment: El Hacker reads MIT source in an evening, El Crítico and La Jefa read a denylist running in-process.
Reasoning and trade-offs · AI analysis
El Hacker is highest and La Jefa lowest, and the split is what counts as containment. He likes it MIT and small enough to read in an evening. El Crítico calls the safety model a denylist enforced in the same process as the agent it constrains, and La Jefa will not present that to a security review.
El Crítico and La Jefa win, and El Hacker is overruled on scope rather than on craft: reading it in an evening is not the same as running it near your data. El Profesor notes no evaluation is offered. Trial only, inside a container, ending when local isolation is a supported capability.