AI coding agents run arbitrary shell commands by design. Ovrin's security model assumes every sandbox will eventually run something it shouldn't — and contains the blast radius to that one sandbox.
Policy is per project and applies to every sandbox booted under it, regardless of template.