capabilities
netrw
Filled is granted to every invocation; the rest need --cap at the point of use.
default
The syscall filter applied to this tool's entry point.
Tools sharing an image do not share a tier.
dotfiles mapped in
read-only unless noted
- ~/.cache/huggingface · writable
env passed through
18 forwarded
ACTIONS_ID_TOKEN_REQUEST_TOKENACTIONS_ID_TOKEN_REQUEST_URLDO_NOT_TRACKGITHUB_ACTIONSHF_DEBUGHF_ENDPOINTHF_HUB_DISABLE_PROGRESS_BARSHF_HUB_DISABLE_SYMLINKSHF_HUB_DISABLE_XETHF_HUB_DOWNLOAD_TIMEOUTHF_HUB_ETAG_TIMEOUTHF_HUB_OFFLINEHF_HUB_VERBOSITYHF_INFERENCE_ENDPOINTHF_OIDC_ID_TOKENHF_OIDC_RESOURCEHF_TOKENTRANSFORMERS_OFFLINE
Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.
HF_HUB_DISABLE_TELEMETRYHF_HUB_DISABLE_UPDATE_CHECK
per-subcommand
no overrides
Every invocation gets the same boundary. Where a tool
needs more for one subcommand only, boks scopes it there
rather than granting it everywhere.