Agents make mistakes and can be manipulated by content they read. Sandboxing limits the damage.
What to Isolate
- Filesystem: restrict access to a working directory; keep credentials, SSH keys and personal files out of reach.
- Network: block access by default and allow specific domains; this limits data exfiltration.
- Processes: run commands as an unprivileged user with resource limits.
- Credentials: give the agent only the scoped, short-lived credentials it needs.
Isolation Options
- Containers: lightweight and common for coding and data agents.
- Virtual machines: stronger isolation for untrusted code.
- Operating-system sandboxing: platform features restricting a process's file and network access.
- Remote environments: disposable cloud workspaces, destroyed after the task.
Disposable by Default
Start each task from a clean environment. Persistent state should be deliberate, not accidental.
Sandboxing and Permissions Together
A sandbox allows more autonomy safely: inside strong isolation, an agent can run commands without asking about each one, because the blast radius is contained.
Test the Boundaries
Try to escape the sandbox — reading secrets, contacting unapproved hosts — before trusting it.