The sandbox needs to be one an agent can't break out of – otherwise it's not a sandbox
@simonw
-
Verify Critical Systems Yourself Don’t Trust Documentation
By
–
Right, and those misunderstandings cost him his database You can't ever trust documentation, you have to prove to yourself that things this critical work the way you think they work
-
Designing safe environments for AI agent failures
By
–
AI agents make mistakes all the time – you have to assume they will make mistakes, and then design their environment so that when they do they can't delete your production database
-
Classifying Dangerous Code Execution Patterns in Python
By
–
Can that classify dangerous versions of something like "uv run python -c 'import graphql; graphql.delete(…)" ?
-
Safe AI Code Generation Platforms: Opportunity and Challenge
By
–
I agree with the general idea that the opportunity (and the challenge) to make safe production vibe coding platforms is enormous
-
Agent Frameworks Need Built-in Sandboxing Best Practices
By
–
I agree, I think every agent framework should come with best-in-class sandboxing out of the box Currently, setting up a sandbox is mostly left as an exercise for the user, and doing that well is really difficult
-

Agent Security: Protecting Production Credentials and Backups
By
–
The conclusions here feel wrong to me. The two lessons I see are: 1. Don't run agents anywhere they might be able to access production environment credentials – it's on you to know which credentials those are 2. Keep tested backups that are independent from your production host
-
DeepSeek-V4-Flash 2bit quantized model released on Hugging Face
By
–
I am refreshing https://
huggingface.co/mlx-community/
DeepSeek-V4-Flash-2bit-DQ
… with excitement waiting for the files to land! -
Hugging Face Models Directory Should Support Quantization Filtering
By
–
Ideal fix would be for the HF models directory to grow a direct understanding of the structure of those kinds of repos and treat them as individual models that can be listed separately, including filter by quantization type
-
ChatGPT Images 2.0 Autonomously Added Humorous Sign Text
By
–
Important: it has been confirmed that ChatGPT Images 2.0 added the "Why are you like this" sign of its own accord