The products, in the setups people run them in
A profile is one product in one configuration — Claude Code with confirmations on is a different animal from Claude Code with them off, and the same product in a vendor's container is different again. Nine so far. The one you use is probably close to one of them, and the game says so when it is playing you against a stand-in.
| Profile | Surface | Can reach | With nothing in the way | Cannot be undone | Measured |
|---|---|---|---|---|---|
| Claude Code — web container | agentbox | 15 | 10 | 7 | 13/15 |
| Claude Code — local · confirm off | cli | 16 | 14 | 8 | 0/16 |
| Claude Code — local · confirm on | cli | 16 | 13 | 8 | 0/16 |
| Claude Desktop — local tools | desktop | 10 | 6 | 5 | 0/10 |
| Claude.ai — connectors on | web | 5 | 1 | 3 | 0/5 |
| Browser extension — all sites | extension | 3 | 2 | 3 | 0/3 |
| Scheduled job — service account | service | 7 | 7 | 4 | 0/7 |
| GitHub Actions — hosted runner | ci | 8 | 7 | 3 | 8/8 |
| ChatGPT — no connectors | web | 1 | 1 | 0 | 0/1 |
Can reach counts capabilities in the grant. With nothing in the way is the subset with no control at all on the path. Cannot be undone is the subset whose effect is irreversible. Measured is how many of the grant's rows rest on a probe run rather than an inference.
Something missing?
A product you use that is not here, or a setup of one that is — a profile is one JSON file, and contributing one is a pull request. A derived profile, honestly labelled, is worth having; a measured one is worth more.