Concepts
The sandbox
What the agent can reach, and what it cannot.
Every command the agent runs gets a fresh container. The repository is bind-mounted read-write, because the harness needs the edits to persist so it can diff them on the host. Everything else is closed.
| Setting | Effect |
|---|---|
| read-only rootfs | The image layer cannot be modified |
| --network none | No egress unless a call explicitly allows it |
| --cap-drop ALL | Every Linux capability is dropped |
| mem-limit | Memory bombs are OOM-killed rather than starving the host |
| pids-limit | Fork bombs collapse at the cap |
| fresh container | One --rm container per command; no state carries over |
Verified adversarially
The sandbox was probed with deliberate attacks rather than assumed secure: escape attempts against host mounts, the PID namespace, the Docker socket and cross-container networking, plus resource exhaustion. All 24 sequential attacks held, as did 78 concurrent hostile runs.