The Hallway Track

sandboxing

21 tracked signals on sandboxing.

Breaking Claude Code Opus 5 Auto Mode

Simon Willison · Aug 27, 2026

Prompt injection attack bypasses Claude Code Auto Mode with 80% success rate

“The safety mechanism itself can become part of the failure. The classifier allowed the creation of the malware process, but then it blocked the command intended to stop it!”
Quoting Akshat Bubna

Simon Willison · Jul 28, 2026

OpenAI's rogue agent exploited an unauthenticated Modal customer endpoint to run arbitrary code

“We're aware a Modal customer published an unauthenticated endpoint that allowed ​anyone on the internet to use ​their ⁠sandboxes for code execution. This was used by the rogue agent. Modal's ⁠platform ​or isolation were not ​compromised in anyway.”
Quoting Matthew Green

Simon Willison · Oct 01, 2026

Sandboxed AI agents can spread worm payloads via shared resources like email and documents

“Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent.”
Quoting Thomas Ptacek

Simon Willison · Jul 22, 2026

2025 open-weight models could already execute sandbox escapes and network hacks with a pentest harness

“I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes.”
smolmachines / smolvm as a sandbox for untrusted Python & JavaScript

Simon Willison · Aug 19, 2026

Claude Fable 5 autonomously pivoted to GitHub Actions when local sandbox lacked KVM support

“This Claude Code container: Linux 6.18.5-fc-v20 (itself a Firecracker guest), 4 vCPU, 15GB RAM. No /dev/kvm, no vmx/svm CPU flags → no nested virt.”
LangSmith Sandboxes: A Secure Computer for Your Agent

LangChain · Jul 20, 2026

LangSmith Sandboxes gives AI agents isolated, scalable compute environments spinning up in under a second

“The question isn't whether agents need computers. It's how you give them one, safely.”
OpenClaw + Windows: Microsoft Build 2026

Microsoft Developer (Build) · Jun 03, 2026

Microsoft announced OpenClaw runs on Windows with a native companion app sandboxed via MXC execution containers.

“we are really thrilled uh to announce that open claw runs on Windows leveraging MXC”
How we contain Claude across products

Simon Willison · May 30, 2026

Anthropic published detailed documentation of how it sandboxes Claude agents across its products.

“if credentials never enter the sandbox, they can't be exfiltrated, regardless of whether the cause is a user, a model finding a “creative” path, or an attacker.”
How Benchling secured multi-tenant AI agents with Amazon Bedrock AgentCore

AWS Machine Learning Blog · Sep 21, 2026

Benchling secured multi-tenant AI agent code execution at scale using Amazon Bedrock AgentCore with zero security incidents.

“Today, this architecture processes more than 600 code execution sessions per day across more than 250 tenants per week with zero security incidents.”
Quoting Jeremy Morrell

Simon Willison · Aug 19, 2026

LLMs enable a new era of extensible software by lowering the cost of authoring user extensions

“My hypothesis is that there is a new opportunity for Extensible Software on the web. LLMs radically lower the cost of authoring extensions, and modern sandbox primitives lower the deployment cost and provide good security boundaries.”
Running Python code in a sandbox with MicroPython and WASM

Simon Willison · Jun 06, 2026

Simon Willison released micropython-wasm, an alpha sandbox for safely running Python code via MicroPython in WebAssembly.

“I'd love to be able to run plugin-style code in an environment where it is unable to read unapproved files, connect to a network, or generally operate in a way that's risky or harmful to the rest of the application or the user's computer.”
datasette-agent-micropython 0.1a0

Simon Willison · Jun 02, 2026

Datasette Agent gets a MicroPython sandbox for safe AI-generated code execution

“GPT-5.5 has so far failed to break out of the sandbox!”
How I Learned to Stop Worrying and Love the Sandbox — Matt Brockman, E2B

Greg Brockman · AI Engineer · Oct 05, 2026

E2B provides cloud sandbox environments enabling AI agents to safely execute arbitrary code in isolation

“What we see now with modern agents is like some magical creature in the cloud that does a lot of cool things, and one of them is writing code.”
micropython-wasm 0.1a1

Simon Willison · Jun 02, 2026

micropython-wasm 0.1a1 released with fixes for datasette-agent-micropython integration

micropython-wasm 0.1a0

Simon Willison · Jun 02, 2026

Simon Willison releases MicroPython WASM sandbox for safe Python code execution

micropython-wasm 0.1a2

Simon Willison · Jun 06, 2026

Simon Willison released micropython-wasm 0.1a2, adding a CLI to the sandboxed MicroPython tool.

“I added a CLI to micropython-wasm, inspired by the first draft of the blog entry when I realized it would be a great way to illustrate the Try it yourself section.”