sandboxing

Tag

Cards List
#sandboxing

Why AI Agents Need a Two-Tier Architecture

Reddit r/AI_Agents ↗ · 2026-07-24

This article discusses the security risks of running AI agents with tool execution on a single server and proposes a two-tier architecture that separates prompt evaluation from code execution to mitigate prompt injection and malicious code attacks.

0 favorites 0 likes
#sandboxing

Wanix — Wasm-native Unix sandboxing for the web

Lobsters Hottest ↗ · 2026-07-23 Cached

Wanix is a Wasm-native Unix sandboxing tool that lets you run and interact with real Wasm and x86 programs entirely in the browser using Web Components, inspired by Plan 9.

0 favorites 0 likes
#sandboxing

Quoting Thibault Sottiaux

Simon Willison's Blog ↗ · 2026-07-16 Cached

Thibault Sottiaux describes a bug where GPT-5.6 unexpectedly deletes files when full access mode is enabled without sandboxing protections, caused by the model attempting to override $HOME and mistakenly deleting it.

0 favorites 0 likes
#sandboxing

A Measurement Study on the Adoption of Pledges and Unveils in the OpenBSD Operating System

Lobsters Hottest ↗ · 2026-07-07 Cached

This paper presents a longitudinal measurement study on the adoption of pledge and unveil system calls in OpenBSD, finding that adoption has steadily grown and that the system calls are relatively easy to adopt, contrary to common beliefs about sandboxing difficulties.

0 favorites 0 likes
#sandboxing

@swyx: for what it's worth, i only invite double-length track keynotes when I'm very sure that both speaker and content deserv…

X AI KOLs Timeline ↗ · 2026-07-02 Cached

At the AIE conference, double-length keynotes on sandboxing and world models by @chrmanning and @abshkbh were well-received, drawing a large in-person and online audience.

0 favorites 0 likes
#sandboxing

Artificial adventures

Lobsters Hottest ↗ · 2026-07-02 Cached

The author shares their experience using various AI coding assistants (Claude Code, Codex, Pi) for code review and refactoring, finding frontier models surprisingly effective at catching subtle bugs but noting the lower quality and erratic behavior of some tools.

0 favorites 0 likes
#sandboxing

@alswl: Is there any community solution to run Claude Code and Codex in a container (or virtualized environment) as a local tool, like Vagrant back in the day? I'm increasingly concerned about the high permissions and unpredictability of agent software.

X AI KOLs Timeline ↗ · 2026-06-30 Cached

The user asks if there is a local tool similar to Vagrant that can run Claude Code and Codex in containers or virtualized environments, to alleviate concerns about excessive permissions and unpredictability of agent software.

0 favorites 0 likes
#sandboxing

After going through ~15 agentic-loop papers (the wins and the failures), the thing that predicts success is the verifier, not the model

Reddit r/AI_Agents ↗ · 2026-06-27

A multi-tweet analysis of ~15 agentic-loop papers concludes that the verifier, not the model, is the key predictor of success, with examples showing that robust, non-gamable checks (e.g., compilers, tests, verifiable rewards) dramatically improve performance, while failures stem from lack of such verifiers or gaming vulnerabilities.

0 favorites 0 likes
#sandboxing

llama.cpp's web UI now supports executing model generated JavaScript in the browser, through Web Workers (opt in)

Reddit r/LocalLLaMA ↗ · 2026-06-24

llama.cpp's web UI now supports executing model-generated JavaScript in a sandboxed iframe via Web Workers, enabling lightweight agentic code execution as an opt-in feature.

0 favorites 0 likes
#sandboxing

Show HN: Homebrew 6.0.0

Hacker News Top ↗ · 2026-06-11 Cached

Homebrew 6.0.0 introduces tap trust security, a new default internal JSON API for faster updates, Linux sandboxing via Bubblewrap, and various improvements based on user survey feedback.

0 favorites 0 likes
#sandboxing

Dancing mad with sandboxing

Lobsters Hottest ↗ · 2026-06-07 Cached

A technical blog post discussing the complexities and frustrations of implementing sandboxing techniques for security.

0 favorites 0 likes
#sandboxing

@motatoeshq: How we're scaling http://opencomputer.dev to 1M sandboxes

X AI KOLs Timeline ↗ · 2026-06-07 Cached

OpenComputer offers long-running, persistent cloud VMs for AI agents, enabling stateful, always-on compute with dynamic resizing, as an alternative to ephemeral sandboxes.

0 favorites 0 likes
#sandboxing

@Hevalon: this tuesday, i'm publishing a guide on how to build a complete Agentic system with a harness to support sandboxing, pa…

X AI KOLs Timeline ↗ · 2026-06-07 Cached

A guide on building a secure agentic system with sandboxing, parallel sub-agents, tool calling with control policies, inference routing, and protection against injection and role escalation attacks, to be published by Evangelos Pappas.

0 favorites 0 likes
#sandboxing

micropython-wasm 0.1a2

Simon Willison's Blog ↗ · 2026-06-06 Cached

MicroPython ported to WebAssembly as a tool for sandboxed Python execution in the browser.

0 favorites 0 likes
#sandboxing

datasette-agent-micropython 0.1a0

Simon Willison's Blog ↗ · 2026-06-02 Cached

Datasette-agent-micropython 0.1a0 is an early alpha release that integrates Micropython into Datasette, utilizing sandboxing and WebAssembly for safe execution.

0 favorites 0 likes
#sandboxing

micropython-wasm 0.1a1

Simon Willison's Blog ↗ · 2026-06-02 Cached

micropython-wasm 0.1a1 is an alpha release that ports MicroPython to WebAssembly, enabling Python execution in web browsers with sandboxing capabilities.

0 favorites 0 likes
#sandboxing

micropython-wasm 0.1a0

Simon Willison's Blog ↗ · 2026-06-02 Cached

micropython-wasm 0.1a0 released, enabling MicroPython to run in WebAssembly environments for sandboxing and portability.

0 favorites 0 likes
#sandboxing

Agent libOS: A Library-OS-Inspired Runtime for Long-Running, Capability-Controlled LLM Agents

Hugging Face Daily Papers ↗ · 2026-06-02

Agent libOS introduces a library-OS-inspired runtime substrate for LLM agents, treating agents as schedulable processes with explicit capabilities, lifecycle management, audit records, and human approval queues. The design shifts the trust boundary from tool dispatch to runtime primitives, enabling long-running agents to be scheduled, authorized, resumed, and audited safely.

0 favorites 0 likes
#sandboxing

How we contain Claude across products

Simon Willison's Blog ↗ · 2026-05-30 Cached

Anthropic published a detailed engineering overview of the sandbox techniques used to contain Claude across its products including Claude.ai, Claude Code, and Claude Cowork, covering process sandboxes, VMs, filesystem boundaries, and egress controls. The article explains the rationale and technologies (gVisor, Seatbelt, Bubblewrap) and mentions the srt open-source tool.

0 favorites 0 likes
#sandboxing

Is anyone interested in seeing how advanced companies are actually running agents in production?

Reddit r/AI_Agents ↗ · 2026-05-26

The author, working at an AI infrastructure company, observes that running AI agents in production is less about the model and more about environment, access control, isolation, and safe state management, and asks if the community wants detailed architecture patterns.

0 favorites 0 likes
← Previous
Next →
← Back to home

Submit Feedback