In normal words
Glossary
The talk is built from scratch for a mixed audience, so here is every term it leans on, in one place.
- Harness
- The word gets used two ways in the talk. One is whatever decides what an agent may do: your approvals, a built in sandbox, a proxy. The other is the software loop around the model, where Agent = Model + Harness. Claude Code is a harness in that second sense.
- Agent vs. workflow
- A workflow follows a path of code that somebody wrote in advance. An agent lets the model steer. It decides which tools to call and when, in a loop.
- Soft rules
- Prompts, approvals and guardrails that live inside the harness. They are requests, so a model can in principle be talked out of them.
- Hard walls
- A sandbox, or any boundary enforced outside the model's control. “Please don't” is a request. A wall is a fact.
- Lethal trifecta
- Simon Willison's name for a dangerous combination: private data, exposure to untrusted content, and a way to send data out. An agent with all three is one prompt injection away from leaking that data.
- Rule of Two
- Meta's design rule. Of the trifecta's three legs, let an agent have two at most.
- Isolation ladder
- More isolation is better, and it costs something. The rungs run from nothing, to OS level tools (Seatbelt or bubblewrap), to a container, then gVisor, then a microVM, then a separate machine. Each step costs speed and setup effort and puts more distance between you and the agent.
- Container escape
- A container shares the host's kernel, so a kernel or runtime bug can let a process break out of it. This has really happened, as the runc CVEs show.
- microVM
- A very small virtual machine with its own kernel, like Firecracker. That makes it a real boundary. AWS built Firecracker for Lambda because containers weren't enough. Docker's agent sandboxes run on microVMs, not containers.
- Brain and hands
- Anthropic's split for managed agents. The model, the brain, never holds credentials. The sandbox, the hands, holds them and does the acting.
- Approval fatigue
- Ask people often enough and they start clicking “allow all”, or they switch the sandbox off. A sandbox that removes the need to ask is a safety feature as well as a convenience.
- srt (sandbox runtime)
- Anthropic's lightweight sandbox command. Reads are open by default, and writes and network access are blocked by default. It always protects .zshrc, .gitconfig and .git/hooks.
- sbx
- Docker's agent sandbox tool. It runs the agent inside a real microVM, with rules for files, network and resources.