Sandbox mode doesn't allow deleting files in the workspace?

Is it expected behavior that when I have an agent “Sandboxed” (Terminal Command Auto Execution = “Always Proceed”) that I can’t have scripts that create and delete a file in my own workspace directory? (without explicitly whitelisting each subdirectory)

I’m wondering if I’m doing something wrong…