> The real key materializes only when the sandbox makes an outbound request to an approved host. If prompt-injected code tries to exfiltrate that placeholder to evil.com? Useless.
That seems clever.
> via an outbound proxy similar to coder/httpjail
looks like AI slop ware :( I hope they didn't actually run it.