t-707
Sandbox run_bash CWD to user workspace, blocklist dangerous commands, restrict read/write_file to user workspace + shared paths. Owner unrestricted.
Ava verified: commit found in live history referencing this task/feature. Moving to Verified.
Ava verified: commit found in live history referencing this task/feature. Moving to Verified.