In the current version it seems the agent can run rm -r without user explicitly press the allow button, it doesn’t feel safe.
Even it said running in sandbox, but it actually delete the files in the project, and seems not a something that can be “keep/reject” after it do so.