logoalt Hacker News

embedding-shapetoday at 2:08 PM0 repliesview on HN

Bit more general; don't run agents without some sort of restriction to what they can do provided by the OS in some way. Containers is one way, VMs another, most cases it's enough with just a chroot and using the unix permission system the rest of your system already uses.