ReadonlyallowedWhether the operation is allowed.
Optional ReadonlyreasonDenial reason if not allowed.
ReadonlypolicyPolicy that was applied.
ReadonlyviolationsViolations found.
Optional ReadonlyconfigurationConfiguration mismatches the executor surfaces to operators — capabilities
declared in the policy but unenforceable because the corresponding
allowlist is empty (e.g. process_spawn set but allowedCommands: []).
Source: #2428 ask 1. Not security violations; informational only.
Result of sandbox policy evaluation.