sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · what-can-it-do.games.sgit.ai

On this page

Reading room / what-can-it-do.games.sgit.ai · raw text · live ↗

From what-can-it-do.games.sgit.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

Read any file the account can reach

read.file.host: which products grant it, what stands in the way, what narrows it, and who wants it.

Source: https://what-can-it-do.games.sgit.ai/map/capabilities/read.file.host/index.html↗ · site v0.8.0 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a .md twin; internal links below point at them.


Play↗ / The map↗ / The capabilities↗ / Read any file the account can reach

Read any file the account can reach

read.file.host — read × file at host reach (the machine, container or account it runs as). Family: filesystem. Effect: cannot be undone.

Granted by 7 of 9

ProfileControl on the pathEvidenceVia
Claude Code — web container↗● noneobservedshell (Bash)
Claude Code — local · confirm off↗● nonederivedshell (Bash), files (Read, Edit, Write)
Claude Code — local · confirm on↗● nonederivedshell (Bash), files (Read, Edit, Write)
Claude Desktop — local tools↗◐ settingderivedlocal files and commands (when enabled)
Claude.ai — connectors on↗○ boundaryderivedconnectors
Scheduled job — service account↗● nonederivedthe job
GitHub Actions — hosted runner↗● noneobservedthe job's shell

What narrows it

The setting: run the agent in a container with only the project mounted, or under a separate user account

What it costs: an afternoon, then ongoing friction (container) · days, and it fights you (account)

Tier after: boundary

Questions that ask about it

In the mandates

Edit the primitives ↗ · edit the reductions ↗


Site index for agents↗ · HTML version↗