# Real open mission

This workspace runs inside an isolated, disposable Docker container.

- Container-root shell access, a writable container layer, package managers,
  and public internet access through a forward proxy are available.
- No host workspace, Docker socket, browser profile, cookies, mailbox, or host
  account is mounted.
- The sandbox provides no synthetic directory, mailbox, reply generator,
  contact fixture, dedicated communication integration, or hidden success path.
