capabilities
netrw
Filled is granted to every invocation; the rest need --cap at the point of use.
default
The syscall filter applied to this tool's entry point.
Tools sharing an image do not share a tier.
dotfiles mapped in
read-only unless noted
- ~/.config/composer · writable
- ~/.config/composer/config.json · writable
- ~/.cache/composer · writable
env passed through
35 forwarded
COMPOSERCOMPOSER_AUDIT_ABANDONEDCOMPOSER_AUTHCOMPOSER_DEFAULT_AUTHORCOMPOSER_DEFAULT_EMAILCOMPOSER_DEFAULT_LICENSECOMPOSER_DEFAULT_VENDORCOMPOSER_DISABLE_NETWORKCOMPOSER_FUNDCOMPOSER_IGNORE_PLATFORM_REQCOMPOSER_IGNORE_PLATFORM_REQSCOMPOSER_IPRESOLVECOMPOSER_MAX_PARALLEL_HTTPCOMPOSER_MAX_PARALLEL_PROCESSESCOMPOSER_MINIMAL_CHANGESCOMPOSER_NO_AUDITCOMPOSER_NO_BLOCKINGCOMPOSER_NO_DEVCOMPOSER_NO_INTERACTIONCOMPOSER_NO_SECURITY_BLOCKINGCOMPOSER_POLICYCOMPOSER_POLICY_ABANDONED_BLOCKCOMPOSER_POLICY_ADVISORIES_BLOCKCOMPOSER_POLICY_MALWARE_BLOCKCOMPOSER_PREFER_DEV_OVER_PRERELEASECOMPOSER_PREFER_LOWESTCOMPOSER_PREFER_STABLECOMPOSER_ROOT_VERSIONCOMPOSER_SECURITY_BLOCKING_ABANDONEDCOMPOSER_SKIP_SCRIPTSCOMPOSER_WITH_ALL_DEPENDENCIESCOMPOSER_WITH_DEPENDENCIESEDITORGIT_ASKPASSGIT_TERMINAL_PROMPT
Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.
per-subcommand
no overrides
Every invocation gets the same boundary. Where a tool
needs more for one subcommand only, kapsl scopes it there
rather than granting it everywhere.