
@liran_tal Sandbox is table stakes. I’d treat skills as executable dependencies with identity attached, then make provenance and token scope the control plane. The ugly part is egress, because a harmless skill becomes interesting once it can call out with someone else’s context.
English




















