Skip to content
Concepts

The sandbox

What the agent can reach, and what it cannot.

Every command the agent runs gets a fresh container. The repository is bind-mounted read-write, because the harness needs the edits to persist so it can diff them on the host. Everything else is closed.

SettingEffect
read-only rootfsThe image layer cannot be modified
--network noneNo egress unless a call explicitly allows it
--cap-drop ALLEvery Linux capability is dropped
mem-limitMemory bombs are OOM-killed rather than starving the host
pids-limitFork bombs collapse at the cap
fresh containerOne --rm container per command; no state carries over

Verified adversarially

The sandbox was probed with deliberate attacks rather than assumed secure: escape attempts against host mounts, the PID namespace, the Docker socket and cross-container networking, plus resource exhaustion. All 24 sequential attacks held, as did 78 concurrent hostile runs.