- The message queue is not persisted across restarts. Queued-but-unsent prompts are dropped; active runs re-attach from session history.
- Role names are not accepted for role configuration; use role IDs.
- The finalization footer shows cost and in/out tokens. Cache reads and
writes are tracked in
/costbut are not rendered in the footer. - Access control is global across guilds.
ACCESS_ROLE_ID,BLOCK_ROLE_ID, andOWNER_ROLE_IDapply to every configured guild; per-guild roles are not supported. A configured guild the bot cannot see is skipped at startup with a warning. - Provider secrets are host-only. Managing
sbx secretfrom Discord is deferred; register credentials on the host. - Not yet implemented: per-user command rate limiting, sandbox disk-usage
warnings, and
DATA_DIRcloud-sync detection. KeepDATA_DIRout of synced folders yourself. - Some checks are host-only. The
sbxspike,sbx policy lssemantics, Windows path mapping, and live Discord behavior are exercised on the host, not in the Linux test suite.
Related
- Commands — the current surface and what is deferred.
- Configuration — the variables behind these limits.