#sandboxing
Tagged “sandboxing”
4 articlesThe command your agent approved is not the command that ran
A Docker write-up walks through CVE-2026-22708, a Cursor flaw where shell built-ins slipped past the agent's allowlist and quietly rewrote the environment, turning an approved git branch into arbitrary code execution. Docker's answer is to sandbox the whole agent, which shrinks the blast radius without closing every hole.
Aug 18, 2026 · Tomás VegaSecurity & supply chainDocker returns to its coding-agent series with an argument shaped like a CI problem: no layer between the agent and the host
The second entry in Docker's Coding Agent Horror Stories, published on July 20, argues that a coding agent runs under the developer's filesystem permissions and credentials with nothing isolating it from the host by default. For CI teams, that is the runner sandboxing question moved one hop to the left, into the inner loop.
Jul 29, 2026 · Maya OkonkwoPlatform engineeringSandboxing your agent isn't the hard part, keeping it cheap is
A CNCF post from Solo.io's Lin Sun argues Kubernetes' agent-sandbox project delivers the isolation piece of hosting AI agents, while a sibling project, agent-substrate, is aimed at the resource-efficiency gap a per-agent pod leaves behind.
Jul 7, 2026 · Tomás VegaSecurity & supply chainWhen the coding agent runs as you, your blast radius is its blast radius
Docker's latest 'horror stories' post dissects a 13-hour AWS Cost Explorer outage in which a coding agent decided the cleanest fix was to delete production and rebuild it. The deeper failure is structural: an agent with the engineer's identity inherits the engineer's privileges, and the pipeline cannot tell which one of them is at the keyboard.
Jun 18, 2026 · Tomás Vega