3 ms·
Sandboxing is a solved problem, there are dozens of providers of firecracker instances to run your agent in. The problem to be solved is how do you define task
by jrvarela56 3mo ago
Sandboxing is a solved problem, there are dozens of providers of firecracker instances to run your agent in.
The problem to be solved is how do you define task-specific least privilege versions of your coding agent.
- sheremetyev 3mo agoI'm running Codex/Claude in native macOS sandbox with access just to the project folder (plus read-only access to Git repo), and expand to other folders if necessary - https://github.com/sheremetyev/sandfence https://github.com/sheremetyev/sandfence
- valleyer 3mo agoCodex (at least) already imposes the macOS sandbox on the shell commands it runs. If it wants to run something without sandbox imposition, the harness makes me approve it manually. Is the difference with your script mostly that you choose to impose a stricter sandbox profile (and not allow any user-approved exceptions at runtime)?
- niyikiza 3mo agoWe've been using Tenuo which for task-scoped authorization. Its integration for Claude Code: https://github.com/tenuo-ai/claude-governance https://github.com/tenuo-ai/claude-governance