Read + probe only against your infrastructure
The agent runs arbitrary code inside its own sandbox because reproduction sometimes needs it. Against your systems it can do exactly two things: read-only probe handshakes and named replica queries.
- No DNS change, no cert reattach, no redeploy — no mutation path exists
- No write-capable credential is ever loaded into the sandbox environment
- Probes are GET or TLS handshake only, against validated public DNS names
- IPs, localhost, and .local or .internal hosts are rejected before the sandbox runs