Tag
Microsoft open-sourced the Agent Governance Toolkit, a governance layer for AI agents that enforces policies, identity, sandboxing, and audit logs to ensure safe and compliant autonomous agent operations.
A blog post discussing techniques for dropping privileges in Go programs to enforce the principle of least privilege, including chroot and user switching.
Context Mode is a tool that solves AI agent context problems by sandboxing tool outputs and persisting sessions, achieving up to 98% compression of Playwright snapshots and using BM25 retrieval to reduce context window usage. It supports 15 platforms including Claude Code, Gemini CLI, VS Code Copilot, and is used by major tech companies.
This reference implementation demonstrates how to run an LLM agent securely within a local sandbox to process and analyze various document types using Rust, LiteParse, and microsandbox. The open-source CLI leverages OpenAI's GPT models and native bash commands to perform file retrieval and analysis in an isolated environment.
Article advocates Firejail as a mature Linux sandboxing tool to restrict program network, filesystem and hardware access without needing new display tech like Wayland.
A technical guide on using microvm.nix on NixOS to create ephemeral VMs for safely running coding agents without access to personal files.
OpenShell is a secure runtime from NVIDIA for managing autonomous AI agents, providing kernel-level enforcement and formal verification to enforce policies safely.
Open Interpreter is a coding agent optimized for low-cost models, supporting multiple harnesses and native sandboxing on macOS, Linux, and Windows.
Anthropic introduces sandboxing features for Claude Code, including filesystem and network isolation, to enhance security and reduce permission prompts by 84%.