21 tracked signals on sandboxing.
Breaking Claude Code Opus 5 Auto Mode
Simon Willison · Aug 27, 2026
Prompt injection attack bypasses Claude Code Auto Mode with 80% success rate
“The safety mechanism itself can become part of the failure. The classifier allowed the creation of the malware process, but then it blocked the command intended to stop it!”
Quoting Akshat Bubna
Simon Willison · Jul 28, 2026
OpenAI's rogue agent exploited an unauthenticated Modal customer endpoint to run arbitrary code
“We're aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal's platform or isolation were not compromised in anyway.”
YOLO Mode, Safely: MicroVM Sandboxes for Any Agent — Rowan Christmas, Docker
AI Engineer · Oct 03, 2026
Docker's new SBX microVM sandbox secures AI agents from local data exfiltration risks.
“What if I try to hack myself?”
Quoting Matthew Green
Simon Willison · Oct 01, 2026
Sandboxed AI agents can spread worm payloads via shared resources like email and documents
“Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent.”
Quoting Thomas Ptacek
Simon Willison · Jul 22, 2026
2025 open-weight models could already execute sandbox escapes and network hacks with a pentest harness
“I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes.”
How Many Credentials Should Your AI Agent Have? Zero. — Jim Clark, Docker
AI Engineer · Oct 06, 2026
AI agents should operate with zero credentials, secured via sandboxes and MCP gateways
“Agents do a lot more than I thought...than I expected them to do.”
smolmachines / smolvm as a sandbox for untrusted Python & JavaScript
Simon Willison · Aug 19, 2026
Claude Fable 5 autonomously pivoted to GitHub Actions when local sandbox lacked KVM support
“This Claude Code container: Linux 6.18.5-fc-v20 (itself a Firecracker guest), 4 vCPU, 15GB RAM. No /dev/kvm, no vmx/svm CPU flags → no nested virt.”
LangSmith Sandboxes: A Secure Computer for Your Agent
LangChain · Jul 20, 2026
LangSmith Sandboxes gives AI agents isolated, scalable compute environments spinning up in under a second
“The question isn't whether agents need computers. It's how you give them one, safely.”
OpenClaw + Windows: Microsoft Build 2026
Microsoft Developer (Build) · Jun 03, 2026
Microsoft announced OpenClaw runs on Windows with a native companion app sandboxed via MXC execution containers.
“we are really thrilled uh to announce that open claw runs on Windows leveraging MXC”
Run Untrusted Agent Code with LangSmith Sandboxes | Interrupt 26
Sundar Pichai · LangChain · Jun 01, 2026
LangChain launched LangSmith Sandboxes to safely run untrusted agent code with sub-second spin-up.
“agents are writing real code today”
How we contain Claude across products
Simon Willison · May 30, 2026
Anthropic published detailed documentation of how it sandboxes Claude agents across its products.
“if credentials never enter the sandbox, they can't be exfiltrated, regardless of whether the cause is a user, a model finding a “creative” path, or an attacker.”
How Benchling secured multi-tenant AI agents with Amazon Bedrock AgentCore
AWS Machine Learning Blog · Sep 21, 2026
Benchling secured multi-tenant AI agent code execution at scale using Amazon Bedrock AgentCore with zero security incidents.
“Today, this architecture processes more than 600 code execution sessions per day across more than 250 tenants per week with zero security incidents.”
Quoting Jeremy Morrell
Simon Willison · Aug 19, 2026
LLMs enable a new era of extensible software by lowering the cost of authoring user extensions
“My hypothesis is that there is a new opportunity for Extensible Software on the web. LLMs radically lower the cost of authoring extensions, and modern sandbox primitives lower the deployment cost and provide good security boundaries.”
Running Python code in a sandbox with MicroPython and WASM
Simon Willison · Jun 06, 2026
Simon Willison released micropython-wasm, an alpha sandbox for safely running Python code via MicroPython in WebAssembly.
“I'd love to be able to run plugin-style code in an environment where it is unable to read unapproved files, connect to a network, or generally operate in a way that's risky or harmful to the rest of the application or the user's computer.”
datasette-agent-micropython 0.1a0
Simon Willison · Jun 02, 2026
Datasette Agent gets a MicroPython sandbox for safe AI-generated code execution
“GPT-5.5 has so far failed to break out of the sandbox!”
How I Learned to Stop Worrying and Love the Sandbox — Matt Brockman, E2B
Greg Brockman · AI Engineer · Oct 05, 2026
E2B provides cloud sandbox environments enabling AI agents to safely execute arbitrary code in isolation
“What we see now with modern agents is like some magical creature in the cloud that does a lot of cool things, and one of them is writing code.”
Extending AI Agents with WebAssembly
Microsoft Developer (Build) · May 26, 2026
WebAssembly components enable sandboxed, portable AI agent extensions via MCP integration.
micropython-wasm 0.1a1
Simon Willison · Jun 02, 2026
micropython-wasm 0.1a1 released with fixes for datasette-agent-micropython integration
micropython-wasm 0.1a0
Simon Willison · Jun 02, 2026
Simon Willison releases MicroPython WASM sandbox for safe Python code execution
datasette-agent-sprites 0.1a0
Simon Willison · May 21, 2026
Datasette releases agent plugin for sandboxed command execution via Fly Sprites
micropython-wasm 0.1a2
Simon Willison · Jun 06, 2026
Simon Willison released micropython-wasm 0.1a2, adding a CLI to the sandboxed MicroPython tool.
“I added a CLI to micropython-wasm, inspired by the first draft of the blog entry when I realized it would be a great way to illustrate the Try it yourself section.”