» Tag
sandboxing
19 postsAI Sandboxing: The Real Risk Lives in Infrastructure, Not the Model
As autonomous AI agents gain access to tools, credentials, and infrastructure, security focus is shifting from model behavior to runtime isolation and sandboxing.
Cloudflare OS Bets on Never Trusting Its AI Agents
Cloudflare OS uses a Gatekeeper to simulate unapproved AI agent actions, sandbox every app, and swap credentials for revocable capabilities.
Code on Incus gives every AI coding agent its own isolated machine
Code on Incus isolates AI coding agents in secure system containers with real-time threat detection, protecting host machines from credential leaks and attacks.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comBuilding Real Human-in-the-Loop Controls for AI Coding Agents
Approval prompts often fail to stop risky AI coding agent actions. Learn a risk-graded approach that prevents, not just reviews, the dangerous ones.
Mohabi: Disaggregating and Sandboxing the Firefox JavaScript Engine
Mohabi advances the disaggregation and sandboxing of the Firefox JavaScript engine.
How Much Isolation Do AI Agents Actually Need?
After Asana's MCP data leak, Sedai engineers debate how much session isolation AI agents truly need, weighing security against cost and speed.
Building Secure AI Sandboxes on Kubernetes
Comparing gVisor, Kata, and Firecracker for running untrusted AI agent code safely on Kubernetes, and why pods alone aren't a security boundary.
Microsoft Quicksand: Sandbox Your AI Agent Without Docker or WSL
Quicksand is a Python API for running AI agents in a sandbox without Docker or WSL.
Runeward: Sandboxing AI Agents with Policy Gates
Runeward provides governed execution cells for AI agents, ensuring secure sandbox environments with policy gates and cost guardrails.