logoalt Hacker News

petesergeantyesterday at 1:29 PM2 repliesview on HN

You should absolutely be running your AI agent inside _some_ kind of sandbox. I put together a list of 19 mostly open-source ones here: https://pleasedonotescape.com/ along with a list of non-project-solutions


Replies

cowpigyesterday at 1:44 PM

`greywall -- opencode`

wren6991yesterday at 1:34 PM

Yeah, I don't think that line quite landed. My point was that LLMs are inherently adversarial (read, "relentlessly proactive") and sandboxing should be a first-class integral feature of your harness, not an afterthought. The problem with dev containers is you still tend to end up with something you care about on the same side of the trust boundary as the LLM.

show 1 reply