sandboxing

Tag

Cards List
#sandboxing

smolmachines / smolvm as a sandbox for untrusted Python & JavaScript

Simon Willison's Blog ↗ · 2026-08-19 Cached

Research demonstrates smolvm's effectiveness as a secure sandbox for untrusted Python and JavaScript code execution using hardware-isolated VMs with features like CPU/RAM limits, network isolation, and filesystem controls.

0 favorites 0 likes
#sandboxing

Quoting Jeremy Morrell

Simon Willison's Blog ↗ · 2026-08-19 Cached

Jeremy Morrell suggests that LLMs and modern sandbox primitives create opportunities for extensible software on the web, allowing users to safely extend applications and gain enhanced capabilities.

0 favorites 0 likes
#sandboxing

An agent nuked half my Obsidian vault. How are you sandboxing your coding agents?

Reddit r/AI_Agents ↗ · 2026-08-19

An AI coding agent accidentally deleted half of an Obsidian vault, prompting a discussion on sandboxing methods to safely integrate coding agents into workflows while preserving data.

0 favorites 0 likes
#sandboxing

Tool Brokers/Gateways

Reddit r/AI_Agents ↗ · 2026-08-16

The article discusses the need for tool gateways to secure AI agents' API access by limiting unpredictable behavior and seeks recommendations for products or libraries that provide such functionality.

0 favorites 0 likes
#sandboxing

A "secure-ish" Pi setup with permission, sandbox, and auto-review

Lobsters Hottest ↗ · 2026-08-13 Cached

A technical guide to hardening the Pi AI agent on a host machine using three extensions that add deterministic permission rules, OS-level sandboxing for shell commands, and automatic review of cross-boundary requests.

0 favorites 0 likes
#sandboxing

I let AI agents run day-to-day operations for my food company. The real risk wasn't bad output, it was write access.

Reddit r/artificial ↗ · 2026-08-12

The author shares their experience running a food company with AI agents, finding that the real risk was not bad output but excessive write access, and that sandboxing with human approval for outbound actions was the key fix.

0 favorites 0 likes
#sandboxing

Agent Safety Should Be a Runtime Contract

Hugging Face Daily Papers ↗ · 2026-08-11 Cached

This paper argues that AI agent safety should be enforced at runtime via preventive controls and verifiable evidence, rather than relying solely on training-time alignment. It grounds the position in audits of safety incidents, false completions, trajectory schemas, and publication trends.

0 favorites 0 likes
#sandboxing

Easy Sandboxing on Linux with Bubblewrap

Lobsters Hottest ↗ · 2026-08-10 Cached

A blog post describing a lightweight sandboxing approach on Linux using Bubblewrap, where a script named 'box' shares the host filesystem read-only and the current directory read-write, allowing host binaries to run in isolation without a separate distro.

0 favorites 0 likes
#sandboxing

Before giving a local AI agent shell access, what security boundary should you enforce?

Reddit r/AI_Agents ↗ · 2026-08-09

A discussion on security boundaries for local AI agents with shell access, covering isolation, least privilege, credential protection, network egress controls, and human approval gates. The author emphasizes that prompt-level instructions are not a real security boundary and asks the community about practical setups.

0 favorites 0 likes
#sandboxing

I care less about autonomous agents now, and more about whether I can trust them

Reddit r/AI_Agents ↗ · 2026-08-09

The author argues that the real challenge for AI agents is not capability but trustworthiness, emphasizing auditing, sandboxing, permissions, and security for agent tooling.

0 favorites 0 likes
#sandboxing

Systemd Dynamic Users (2020)

Lobsters Hottest ↗ · 2026-08-08 Cached

This article explains systemd dynamic users, a feature that creates ephemeral Unix users at runtime for systemd units, removing the need to manually manage service users. It includes configuration examples and use cases.

0 favorites 0 likes
#sandboxing

@Saboo_Shubham_: GitHub Repo:

X AI KOLs Following ↗ · 2026-08-08 Cached

Agent Substrate is a Google open-source runtime that enables high-density lifecycle management for large-scale AI agent deployments, multiplexing many stateful agents onto fewer physical workers via Kubernetes and microVM/gVisor sandboxes with sub-second suspend/resume.

0 favorites 0 likes
#sandboxing

Cloudflare open-sources vibe-coding platform for people who aren't coders

Ars Technica ↗ · 2026-08-06 Cached

Cloudflare open-sourced its internal vibe-coding platform Cloudflare OS, which lets non-developers build apps using AI agents with a secure sandbox architecture based on Dynamic Workers isolates.

0 favorites 0 likes
#sandboxing

Introducing Flex: Let the Model Write the Code (16 minute read)

TLDR AI ↗ · 2026-08-06 Cached

Introduces Flex, a new DSPy module that lets language models rewrite the program code itself rather than just prompts, enabling better optimization, fewer model calls, and safer execution via sandboxing.

0 favorites 0 likes
#sandboxing

@github: Save this for the next time you're in Copilot CLI. Our docs now tell you more about local sandboxing in the terminal, i…

X AI KOLs Timeline ↗ · 2026-08-04 Cached

GitHub announces updates to Copilot CLI documentation covering local sandboxing in the terminal, including how to enable and configure settings.

0 favorites 0 likes
#sandboxing

the anthropic "claude broke into real companies" incident is the best case yet for open, auditable agent activity logs

Reddit r/AI_Agents ↗ · 2026-07-31

A discussion of Anthropic's report on Claude models accidentally accessing real systems during eval runs, arguing that the incidents highlight the need for external, auditable agent activity logs as a fundamental safety primitive.

0 favorites 0 likes
#sandboxing

@rauchg: http://Eve.dev is more fundamental than any other framework we’ve built. It’s the genesis of your company. When you hav…

X AI KOLs Following ↗ · 2026-07-25 Cached

Guillermo Rauch announces Eve.dev, a framework for building durable agents inspired by Next.js, featuring durability, sandboxing, human-in-the-loop, and easy integration with existing Next.js apps.

0 favorites 0 likes
#sandboxing

@rauchg: https://x.com/rauchg/status/2081047912008872293

X AI KOLs Following ↗ · 2026-07-25 Cached

Guillermo Rauch argues that AI agents escaping sandboxes, while concerning, is not a new threat and highlights that Vercel has experienced zero escapes despite heavy AI usage, emphasizing the robustness of existing sandboxing techniques.

0 favorites 0 likes
#sandboxing

Why AI Agents Need a Two-Tier Architecture

Reddit r/AI_Agents ↗ · 2026-07-24

This article discusses the security risks of running AI agents with tool execution on a single server and proposes a two-tier architecture that separates prompt evaluation from code execution to mitigate prompt injection and malicious code attacks.

0 favorites 0 likes
#sandboxing

Wanix — Wasm-native Unix sandboxing for the web

Lobsters Hottest ↗ · 2026-07-23 Cached

Wanix is a Wasm-native Unix sandboxing tool that lets you run and interact with real Wasm and x86 programs entirely in the browser using Web Components, inspired by Plan 9.

0 favorites 0 likes
← Previous
Next →
← Back to home

Submit Feedback