Skip to content
Sandboxing

In normal words

Glossary

The talk is built from scratch for a mixed audience, so here is every term it leans on, in one place.
Harness
The word gets used two ways in the talk. One is whatever decides what an agent may do: your approvals, a built in sandbox, a proxy. The other is the software loop around the model, where Agent = Model + Harness. Claude Code is a harness in that second sense.
Agent vs. workflow
A workflow follows a path of code that somebody wrote in advance. An agent lets the model steer. It decides which tools to call and when, in a loop.
Soft rules
Prompts, approvals and guardrails that live inside the harness. They are requests, so a model can in principle be talked out of them.
Hard walls
A sandbox, or any boundary enforced outside the model's control. “Please don't” is a request. A wall is a fact.
Lethal trifecta
Simon Willison's name for a dangerous combination: private data, exposure to untrusted content, and a way to send data out. An agent with all three is one prompt injection away from leaking that data.
Rule of Two
Meta's design rule. Of the trifecta's three legs, let an agent have two at most.
Isolation ladder
More isolation is better, and it costs something. The rungs run from nothing, to OS level tools (Seatbelt or bubblewrap), to a container, then gVisor, then a microVM, then a separate machine. Each step costs speed and setup effort and puts more distance between you and the agent.
Container escape
A container shares the host's kernel, so a kernel or runtime bug can let a process break out of it. This has really happened, as the runc CVEs show.
microVM
A very small virtual machine with its own kernel, like Firecracker. That makes it a real boundary. AWS built Firecracker for Lambda because containers weren't enough. Docker's agent sandboxes run on microVMs, not containers.
Brain and hands
Anthropic's split for managed agents. The model, the brain, never holds credentials. The sandbox, the hands, holds them and does the acting.
Approval fatigue
Ask people often enough and they start clicking “allow all”, or they switch the sandbox off. A sandbox that removes the need to ask is a safety feature as well as a convenience.
srt (sandbox runtime)
Anthropic's lightweight sandbox command. Reads are open by default, and writes and network access are blocked by default. It always protects .zshrc, .gitconfig and .git/hooks.
sbx
Docker's agent sandbox tool. It runs the agent inside a real microVM, with rules for files, network and resources.