Sandboxing Agents That Run Code
Isolate code executing agents so a bad command cannot reach your files, network or secrets
A taste of a lesson
Our data agent runs Python in a container with internet access so it can install packages. What is the biggest risk?
Open internet plus package installs is the big one. The agent could install a mistyped or invented package name that someone has registered with malicious code, and that code could then send out whatever the container can see. Narrow it: allow outbound traffic only to your package registry or an internal mirror, pre install the common libraries, and require approval for new packages. Check that no API keys sit in environment variables inside the container. What data files does the container currently have access to?
Written by the teacher as an example. In your lesson the tutor answers your own questions, and like any AI it can be wrong.
What you will be able to do
- Explain the risks of code executing agents, including injected and mistaken commands
- Compare containers, virtual machines and hosted sandboxes by isolation strength
- Configure file system, network, resource and user limits for an agent sandbox
- Keep secrets out of reach with short lived tokens or credential proxies
- Design a safe channel for getting results out of the sandbox and reviewed
Lesson plan
- 1 Why code execution changes the risk Understand how running code turns agent mistakes into real damage. Start
- 2 Choosing an isolation boundary Compare containers, virtual machines and hosted sandboxes by strength and cost. Start
- 3 Files, users and resources Limit what the agent can read, write and consume inside the sandbox. Start
- 4 Network egress control Allow only the network access the task needs. Start
- 5 Secrets and credentials Give agents access to services without exposing long lived keys. Start
- 6 Ephemeral runs, approvals and results Run each task fresh, gate risky commands and review outputs before use. Start
Try asking
About this tutor
For engineers building or deploying agents that write and execute code, run shell commands or install packages: coding agents, data analysis agents and automation runners. Code execution makes agents far more capable and far more dangerous. This tutor teaches isolation in layers: containers and virtual machines, file system boundaries, network egress control, resource limits, secret handling, ephemeral environments and command policies. You will compare isolation options by strength and convenience and design a sandbox for a specific agent, including how results get out safely.
Reviews
Students can review a tutor after a paid lesson. Nobody has yet.
About the teacher
I teach people to make AI agents safe, observable and testable before they are trusted with real work
9 tutors 290 lessons taught Sample
My background is in quality assurance and security testing, and I came to agents through the question every tester asks: how do we know this thing works, and what happens when it does not? I teach guardrails, permissions, approval steps, evaluation and trace debugging. My lessons are concrete. We look at a failure, name it, and design the check that...
See Ingrid's profile and tutorsMore like this
Other tutors on the same or nearby topics.