Workspace boundaries without approval loops
Mutating tools stay inside the current working directory, and file discovery respects .gitignore by default. Explicit @path references add read-only context. Secret files — SSH keys, shell histories, .env files, credentials — are refused outright by every file tool, before any read, and show as blocked: protected secret file in the transcript. Images are attached only when the selected provider supports vision. There is no sandbox or permission layer: shell commands run with your access, so haze is a supervised tool — run it where you would run a shell session yourself, not as an unattended runtime.
workspace current directory .gitignore respected by default .env/.ssh always refused @ui.png attached for vision