Free tools Windows power users keep installed
One-click scans. No signup required.
Prevent out-of-scope edits by combining a precise task boundary with controls enforced outside the AI model: limit writable paths and available tools, run commands in an appropriately isolated environment, require review for risky side effects, and inspect the final diff and audit trail. Written instructions tell an agent what you want; they do not, by themselves, stop it from reaching files or services beyond that request.
Define what is in scope before the agent starts
Write down the intended files or directories, permitted operations, and prohibited side effects before handing off the task. For example, distinguish “edit the login form and its tests” from broader permission to modify shared configuration, install packages, run deployment commands, or change unrelated files. If the request leaves those boundaries unclear, narrow it or ask for clarification before enabling broad access.
Treat the task description as the communication layer, not the enforcement layer. OpenAI’s guidance on running Codex safely describes sandbox and approval boundaries; the practical implication is to make the requested scope explicit and then enforce it with permissions and execution controls.
Restrict the paths and tools the agent can use
Give the agent the smallest workspace and tool set that can complete the task. A whole-repository workspace may be necessary for some changes, but it is broader than a selected folder; a general shell permission is broader than permission to use one specific command. Prefer narrower controls when the host supports them.
Recommended Free Tools
#1 Best Overall
- Limit writable paths: Make only the relevant workspace or directories writable where possible. In an agent application, validate the target path and operation before allowing a file-changing tool call.
- Limit available tools: Disable tools the task does not need, such as deployment, package publishing, or broad shell access.
- Use specific permissions: GitHub Copilot CLI documentation describes allowing or denying tools and subcommands, including file-specific write permissions as an example. Its deny rules take precedence over allows. GitHub cautions that broad permission modes belong only in an isolated environment: Allowing and denying tool use.
- Check host-level restrictions: Visual Studio Code says built-in agent tools can be restricted to the current workspace and provides a picker to enable or disable tools. See Secure AI-assisted development.
Do not assume that a model’s promise to stay within scope is equivalent to a permission boundary. If the agent can write elsewhere or invoke a powerful tool, instructions alone may not prevent it from doing so.
Use isolation for commands and side effects
Different isolation mechanisms address different risks. A Git worktree gives a task a separate checkout, helping keep its edits away from your active working tree and reducing interference. It is not, by itself, a security barrier against access to a developer’s home directory, credentials, or network.
For stronger execution boundaries, use OS-level sandboxing or isolated compute where available. Consider which network destinations commands may reach, and keep credentials separate from the environment that runs generated code. OpenAI’s sandbox security guidance discusses isolated compute, approved network access, and credential separation. Visual Studio Code documents worktree sessions separately from OS-level agent sandboxing in its security guidance; they are related controls, not substitutes for one another.
Product support and labels change. The cited Visual Studio Code page describes terminal sandboxing as Preview on macOS, Linux, and WSL2, and Experimental on Windows at the time of its current page content. Check the current documentation for your version and platform before relying on a specific feature.
Validate actions where tools cause side effects
If you build an agent application, enforce policy at the tool that can make a change—not only around the agent’s overall input or final response. OpenAI’s Agents SDK documentation puts it succinctly: “Put validation next to the tool that creates the side effect.” The guardrails and human review guidance notes that agent-level input and output guardrails do not automatically run around every tool call in a manager-style workflow.
For each side-effecting tool, check the proposed target, operation, arguments, identity, and scope. Reject actions that exceed the allowed boundary. Pause ambiguous or high-risk actions for explicit human approval, and fail closed if the review mechanism is unavailable. This is especially important for nested or custom tools: an outer agent check does not necessarily validate every internal call.
Rank #4
Review the diff and keep an audit trail
Before committing, merging, or opening a pull request, inspect the complete diff—not just the files the agent said it changed. Look for unrelated edits, generated files, configuration changes, and unexpected deletions. Use the host’s controls to keep or undo pending edits when available; Visual Studio Code documents diff review and pending-edit controls in its security documentation.
Keep enough logs to reconstruct what happened: the original request, tool calls, approvals, results, and relevant network-policy decisions. OpenAI describes using Codex logs to investigate unexpected activity in Running Codex safely at OpenAI. Logs help explain and investigate mistakes; they do not prevent unauthorized access, so they complement rather than replace permissions and isolation.
Best Value
Choose controls by the risk you need to contain
Compare a setup across the dimensions that affect actual exposure. A written instruction is easy to apply but does not block access; OS-level isolation can enforce a stronger execution boundary but may require more setup. A tool allowlist narrows capabilities, while a workspace boundary narrows where those capabilities can operate.
- Enforcement strength: Is the control an instruction, a tool permission, a workspace restriction, or OS-level isolation?
- Scope granularity: Does it apply to the whole workspace, selected folders, individual tools, or individual tool calls?
- External access: Can commands reach arbitrary network destinations, and are credentials available in the execution environment?
- Approval friction: Does review happen for every action, only sensitive actions, or not at all?
- Review and recovery: Are edits isolated, visible in a diff, auditable, and straightforward to discard?
There is no single product or configuration established as the right choice for every coding agent. The exact steps depend on the agent, host, operating system, and repository layout. For Codex worktree and cloud-environment context, see the OpenAI Help Center overview.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




