This is interesting — kernel-level containment is the right foundation for agent security. I've been thinking about how it fits into a broader stack: containment (what you're building), deterministic policy authorization (Predicate-secure is doing this), and economic accountability for actions that can't be predefined in policy. Wrote up how the three layers complement each other: https://medium.com/p/3dd5e76ebaf1?postPublishedType=initial
selfradiance•43m ago