Sources
References
Core6
- Sajal Sharma, Sandboxing an AI Agent
sajalsharma.com
- DevOps Toolkit video on the isolation ladder
I worked from the captions, and the auto captions spell “harness” as “hardness”.
youtu.be
- Anthropic, Building effective agents
anthropic.com
- Simon Willison, The Lethal Trifecta
simonwillison.net
- Simon Willison on Meta's Rule of Two
simonw.substack.com
- The Attacker Moves Second
It got past 12 published defenses. Most of them had reported near zero attack success, and the adaptive attacks beat them more than 90% of the time.
arxiv.org
Incidents and attacks7
- Wiz on s1ngularity
wiz.io
- The Register on Amazon Q
AWS says the payload was malformed and no customer was affected. So I say “shipped a wiper prompt”, not “wiped”.
theregister.com
- eWeek on Replit
The claims about faked records come mostly from the founder's own posts.
eweek.com
- Invariant on the GitHub MCP vulnerability
invariantlabs.ai
- VentureBeat on Comment and Control
venturebeat.com
- The Hacker News on the GTIG report
thehackernews.com
- SecurityWeek on the null byte bypass
No CVE was assigned and the sources disagree on the patch version. I call it “a bug that was live for months”, not a CVE.
securityweek.com
Tools and docs10
- Anthropic, Claude Code sandboxing
anthropic.com
- Anthropic, Managed Agents (brain and hands)
anthropic.com
- The sandbox runtime README
github.com
- Docker sandboxes, overview
docs.docker.com
- Docker sandboxes, getting started
docs.docker.com
- Docker sandboxes, security
docs.docker.com
- Docker sandboxes, policy
docs.docker.com
- Docker blog, Comparing sandboxing approaches
docker.com
- Docker Sandboxes on Hacker News
A Docker employee confirms the sandboxes are built on microVMs, not containers.
news.ycombinator.com
- Andrew Lock, running agents in a microVM
andrewlock.net