Tag
Research demonstrates smolvm's effectiveness as a secure sandbox for untrusted Python and JavaScript code execution using hardware-isolated VMs with features like CPU/RAM limits, network isolation, and filesystem controls.
Jeremy Morrell suggests that LLMs and modern sandbox primitives create opportunities for extensible software on the web, allowing users to safely extend applications and gain enhanced capabilities.
An AI coding agent accidentally deleted half of an Obsidian vault, prompting a discussion on sandboxing methods to safely integrate coding agents into workflows while preserving data.
The article discusses the need for tool gateways to secure AI agents' API access by limiting unpredictable behavior and seeks recommendations for products or libraries that provide such functionality.
A technical guide to hardening the Pi AI agent on a host machine using three extensions that add deterministic permission rules, OS-level sandboxing for shell commands, and automatic review of cross-boundary requests.
The author shares their experience running a food company with AI agents, finding that the real risk was not bad output but excessive write access, and that sandboxing with human approval for outbound actions was the key fix.
This paper argues that AI agent safety should be enforced at runtime via preventive controls and verifiable evidence, rather than relying solely on training-time alignment. It grounds the position in audits of safety incidents, false completions, trajectory schemas, and publication trends.
A blog post describing a lightweight sandboxing approach on Linux using Bubblewrap, where a script named 'box' shares the host filesystem read-only and the current directory read-write, allowing host binaries to run in isolation without a separate distro.
A discussion on security boundaries for local AI agents with shell access, covering isolation, least privilege, credential protection, network egress controls, and human approval gates. The author emphasizes that prompt-level instructions are not a real security boundary and asks the community about practical setups.
The author argues that the real challenge for AI agents is not capability but trustworthiness, emphasizing auditing, sandboxing, permissions, and security for agent tooling.
This article explains systemd dynamic users, a feature that creates ephemeral Unix users at runtime for systemd units, removing the need to manually manage service users. It includes configuration examples and use cases.
Agent Substrate is a Google open-source runtime that enables high-density lifecycle management for large-scale AI agent deployments, multiplexing many stateful agents onto fewer physical workers via Kubernetes and microVM/gVisor sandboxes with sub-second suspend/resume.
Cloudflare open-sourced its internal vibe-coding platform Cloudflare OS, which lets non-developers build apps using AI agents with a secure sandbox architecture based on Dynamic Workers isolates.
Introduces Flex, a new DSPy module that lets language models rewrite the program code itself rather than just prompts, enabling better optimization, fewer model calls, and safer execution via sandboxing.
GitHub announces updates to Copilot CLI documentation covering local sandboxing in the terminal, including how to enable and configure settings.
A discussion of Anthropic's report on Claude models accidentally accessing real systems during eval runs, arguing that the incidents highlight the need for external, auditable agent activity logs as a fundamental safety primitive.
Guillermo Rauch announces Eve.dev, a framework for building durable agents inspired by Next.js, featuring durability, sandboxing, human-in-the-loop, and easy integration with existing Next.js apps.
Guillermo Rauch argues that AI agents escaping sandboxes, while concerning, is not a new threat and highlights that Vercel has experienced zero escapes despite heavy AI usage, emphasizing the robustness of existing sandboxing techniques.
This article discusses the security risks of running AI agents with tool execution on a single server and proposes a two-tier architecture that separates prompt evaluation from code execution to mitigate prompt injection and malicious code attacks.
Wanix is a Wasm-native Unix sandboxing tool that lets you run and interact with real Wasm and x86 programs entirely in the browser using Web Components, inspired by Plan 9.