frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Why are so many rolling out their own AI/LLM agent sandboxing solution?

17•ATechGuy•1d ago
Seeing a lot of people running coding agents (Claude Code, etc.) in custom sandboxes Docker/VMs, firejail/bubblewrap, scripts that gate file or network access.

Curious to know what's missing that makes people DIY this? And what would a "good enough" standard look like?

Comments

rvz•1d ago
This is no different to people rolling their own and DIY'ing custom cryptography, which is absolutely not recommended.

The question is how easy is it to bypass these DIY 'sandboxes'?

As long as there is a full OS running, you are one libc function away from a sandbox escape.

ATechGuy•1d ago
> As long as there is a full OS running, you are one libc function away from a sandbox escape.

Does this mean, all software in the world is just one function away from escape?

sargstuff•1d ago
Yup. Technically, just one external reference outside of the sandbox environment from within the sandbox environment ("software stargate portal address to alternate environment" / one evaluated part of the s-expression using a system() reference).

Running software is insecure the moment the electrical switch is on / start checking out shrodingers box. Although, reverse shrodingers cat might be more accurate. aka can escape the box if someone peaks from outside the box.

verdverm•1d ago
I started building my own agent when I became frustrated with copilot not reading my instruction files reliably. Looked at the code, and wouldn't you know they let the LLM decide...

Once started down this path, I knew I was going to need something for isolated exec envs. I ended up building something I think is quite awesome on Dagger. Let's me run in containers without running containers, can get a diff or rewind history, can persist and share wvia any OCI registry.

So on one hand, I needed something and chose a technology that would offer me interesting possibilities, and on the other I wanted to have features I don't expect the likes of Microsoft to deliver with Copilot, only one of which is my sandbox setup.

I'm not sure I would call it rolling my own completely, I'm building on established technology (OCI, OCR)

I don't expect a standard to arise, OCI is already widely adopted and makes sense, but there are other popular techs and there will be a ton of reimplementations by another name/claim. The other half of this is that AI providers are likely to want to run and charge money for this, I personally expect more attempts at vendor lock in in this space. In example, Anthropic bought Bun and I anticipate some product to come of this, isolation and/or canvas related

ATechGuy•1d ago
What was the first concrete thing you needed that existing sandboxing tools (Docker/VMs/bwrap) just didn't provide?
verdverm•1d ago
This question reads like HN market research and not genuine curiosity

Go look at what dagger provides over those technologies as a basis for advanced agent env capabilities. I use it for more than just sandboxing with my agent

I would also point out sandboxing is just one feature, that is approaching required status, for an agentic framework and unlikely to be an independent product or solution

kaffekaka•3h ago
Speaking for myself, a bash script and a Dockerfile (coupled with dedicated user on linux system) seemed simpler than discovering and understanding some other, over complicated tool built by someone else. Example: a coworker vibe coded a bloated tool but it was not adapted to other OS:s than his own, it was obviously LLM generated so neither one of us actually knew the code, etc. My own solution has shortcomings too but at least I can be aware of them.

It simply feels as if there is no de facto standard yet (there surely will be).

varshith17•3h ago
Same reason everyone rolled their own auth in 2010, the problem is simple enough to DIY badly, complex enough that no standard fits everyone. My Claude Code needs SSH access but not rm. Your agent needs filesystem writes but not network. There's no "OAuth for syscalls" yet.
verdverm•1h ago
this is the most insightful comment I've heard on this in a while

To me, OCI seems the best foundation to build on. It has the features, is widely disseminated, and we have a lot of practice and tooling already

Tell HN: 2 years building a kids audio app as a solo dev – lessons learned

117•oliverjanssen•20h ago•52 comments

Tell HN: Bending Spoons laid off almost everybody at Vimeo yesterday

382•Daemon404•17h ago•422 comments

Ask HN: Does Apple not have *any* QA for their older macOS releases?

3•richrichardsson•39m ago•0 comments

Ask HN: Why are so many rolling out their own AI/LLM agent sandboxing solution?

17•ATechGuy•1d ago•9 comments

Users don't care about your app's complexity

2•Fh_•56m ago•3 comments

Ask HN: Do you have any evidence that agentic coding works?

419•terabytest•1d ago•417 comments

Ask HN: Does "Zapier for payment automation" exist?

8•PL_Venard•19h ago•10 comments

Ask HN: How do you run parallel agent sessions?

6•Olshansky•2d ago•2 comments

Tell HN: Claude session limits getting small

17•pragmaticalien8•15h ago•13 comments

Ask HN: How are you automating your coding work?

66•manthangupta109•14h ago•75 comments

Do people at Google use Gmail?

2•mr-pink•4h ago•1 comments

Ask HN: What have you built/shipped with Claude Code?

7•blhack•1d ago•3 comments

How do you keep AI-generated applications consistent as they evolve over time?

9•RobertSerber•16h ago•0 comments

Ask HN: Revive a mostly dead Discord server

19•movedx•1d ago•28 comments

Ask HN: What are good resources to get familiar with AI code editors?

8•northfield27•19h ago•6 comments

Ask HN: COBOL devs, how are AI coding affecting your work?

167•zkid18•2d ago•183 comments

Ask HN: Do you protect your client-side JavaScript? Why or why not?

5•nikitaeverywher•1d ago•1 comments

Ask HN: How did Gemini go from being awful to incredible back to awful?

3•wewewedxfgdf•5h ago•4 comments

Tell HN: Avoid Cerebras if you are a founder

29•remusomega•17h ago•15 comments

Tell HN: Claude helped me maintain my old open source project

12•nergal•13h ago•7 comments

Ask HN: How locked down are your work machines?

15•donatj•14h ago•17 comments

Ask HN: How do you audit autonomous AI agent decisions?

3•credentum•8h ago•2 comments

Tell HN: Amazon has deactivated my seller account

74•hacky_engineer•15h ago•72 comments

Ask HN: Vibe-coded prototypes: what happens when they go into production?

4•stosssik•9h ago•1 comments

Ask HN: Are you going to meetups/conferences?

9•carimura•17h ago•5 comments

Ask HN: Why does SOC 2 feel so hard for early-stage startups?

7•asdxrfx•19h ago•3 comments

Ask HN: Which common map projections make Greenland look smaller?

18•jimnotgym•1d ago•17 comments

Ask HN: Anyone seeing copy/paste reliability issues in ChatGPT Web on macOS?

2•sallyrideauto•8h ago•0 comments

Tell HN: ChatGPT needs a persistent workspace layer

7•LostBeacon•12h ago•1 comments

Ask HN: What's your biggest challenge with context engineering for AI agents?

4•karpathunter•17h ago•0 comments