capabilities
browsernetrw
Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.
default
The syscall filter applied to this tool's entry point.
Tools sharing an image do not share a tier.
dotfiles mapped in
read-only unless noted
env passed through
19 forwarded
DO_NOT_TRACKGH_ACCESSIBLE_COLORSGH_ACCESSIBLE_PROMPTERGH_DEBUGGH_ENTERPRISE_TOKENGH_HOSTGH_PROMPT_DISABLEDGH_REPOGH_SPINNER_DISABLEDGH_TELEMETRYGH_TOKENGITHUB_ENTERPRISE_TOKENGITHUB_TOKENHTTPS_PROXYHTTP_PROXYNO_PROXYhttp_proxyhttps_proxyno_proxy
Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.
per-subcommand
grants differ
Where a tool needs more for one subcommand only, kapsl
scopes it there rather than granting it everywhere.
Where it needs less, kapsl takes it away there too.