▲ | miguelspizza a day ago | ||||||||||||||||
It's more providing permission granularity on the action level rather than the sandbox level. Your script might not be able to make external api calls, but there is no way to gate the ability to take destructive action within the webpage. With something like WebMCP you get elicitation and the ability to disable tools from the client. | |||||||||||||||||
▲ | koolala a day ago | parent [-] | ||||||||||||||||
What kind of destructive action do you mean that is so critical? | |||||||||||||||||
|