Sandboxed Agent Execution
Định nghĩa
Sandboxed Agent Execution là việc chạy command, build, test, script hoặc tool call của agent trong môi trường isolated, giới hạn network, filesystem và tài nguyên.
Cách hiểu bằng lời của tôi
Coding agent phải chạy code để verify, nhưng không thể được tin như developer local. Sandbox là ranh giới an toàn: agent vẫn có thể thử build/test, nhưng destructive command, secret access hoặc network exfiltration bị chặn hoặc cần approval.
Bài học từ source
- Cursor xem sandbox như serving infrastructure: cần scheduler, fast provisioning và recycling.
- GitHub dùng nhiều container, firewall, MCP gateway và proxy để agent không trực tiếp chạm secret hoặc network tùy ý.