Skip to content

Sandboxing AI Agents

Isolating agents so their mistakes and any manipulation can't reach sensitive systems: containers, VMs, file and network limits.

Editorial team 1 min read

Agents make mistakes and can be manipulated by content they read. Sandboxing limits the damage.

What to Isolate

  • Filesystem: restrict access to a working directory; keep credentials, SSH keys and personal files out of reach.
  • Network: block access by default and allow specific domains; this limits data exfiltration.
  • Processes: run commands as an unprivileged user with resource limits.
  • Credentials: give the agent only the scoped, short-lived credentials it needs.

Isolation Options

  • Containers: lightweight and common for coding and data agents.
  • Virtual machines: stronger isolation for untrusted code.
  • Operating-system sandboxing: platform features restricting a process's file and network access.
  • Remote environments: disposable cloud workspaces, destroyed after the task.

Disposable by Default

Start each task from a clean environment. Persistent state should be deliberate, not accidental.

Sandboxing and Permissions Together

A sandbox allows more autonomy safely: inside strong isolation, an agent can run commands without asking about each one, because the blast radius is contained.

Test the Boundaries

Try to escape the sandbox — reading secrets, contacting unapproved hosts — before trusting it.

More in Agent harnesses

All Agent harnesses guides →
Agent harnesses Guide · 2 min

What Is an Agent Harness?

The software around a language model that turns it into an agent: the loop, tools, context, permissions and memory.

Agent harnesses 2 min read 27 Sep 2025

Agent harnesses Guide · 1 min

The Agent Loop Explained

The core cycle every agent runs: think, call a tool, observe the result, repeat — and how the loop knows when to stop.

Agent harnesses 1 min read 26 Sep 2025

Agent harnesses Guide · 1 min

Designing Tools for AI Agents

How to write tools agents use well: clear names, precise descriptions, sensible inputs and informative outputs.

Agent harnesses 1 min read 25 Sep 2025

Agent harnesses Guide · 1 min

Context Management in Agent Harnesses

How agents stay effective over long tasks: what to keep in context, what to summarise, and what to store outside.

Agent harnesses 1 min read 24 Sep 2025