diff --git a/src/agents/sandbox/validate-sandbox-security.test.ts b/src/agents/sandbox/validate-sandbox-security.test.ts index 1c3e3fe0676..03992bd996a 100644 --- a/src/agents/sandbox/validate-sandbox-security.test.ts +++ b/src/agents/sandbox/validate-sandbox-security.test.ts @@ -47,6 +47,11 @@ describe("validateBindMounts", () => { it("blocks dangerous bind source paths", () => { const cases = [ + { + name: "host root mount", + binds: ["/:/mnt/host"], + expected: /blocked path "\/"/, + }, { name: "etc mount", binds: ["/etc/passwd:/mnt/passwd:ro"],