What enforces it after that one command?
The sandbox uses the policies already defined in a Stashbase profile, including filesystem restrictions, egress rules, credentials, and MCP tool access.
The agent container has no direct outbound network access. A separate firewall layer allows it to reach only the Stashbase Agent Proxy, where egress and credential policy are enforced.
So the agent gets an environment it can work in, while Stashbase controls what it is actually allowed to access.