logoalt Hacker News

Sharlintoday at 11:58 AM1 replyview on HN

It's definitely not a sandbox if you can just "use python to write files" outside of it o_O


Replies

chonglitoday at 1:41 PM

Hence the article’s security theatre remark.

I’m not sure why everyone seems to have forgotten about Unix permissions, proper sandboxing, jails, VMs etc when building agents.

Even just running the agent as a different user with minimal permissions and jailed into its home directory would be simple and easy enough.

show 3 replies