•11 min
Your Agent Writes Code and Runs It Where Your Secrets Live
The feature that makes a code-writing agent useful, running code it generated a second ago, is also the widest hole in your stack. That code is written from input you do not control, and most teams run it in the same process or a plain container that can read every secret and call any host. Here is how to sandbox agent code execution properly: hard isolation, no credentials inside, a default-deny egress broker, strict resource limits, and a box you throw away after every task.
AI Agents
Security