
The Weekly Dev's Brew
Why AI agents belong in the sandbox | Darren Shepherd
Why buy a sandbox when you can just launch a container? Darren Shepherd spent years at Rancher building on Kubernetes, so sandboxes looked dumb to him. Then he built his own coding agent to run 15 things in parallel without work-tree chaos, and the most interesting part of it turned out to be a sandboxing system. He had proved himself wrong. The sharp part is where the sandbox boundary goes. The common pattern keeps the agent loop outside and sandboxes only its tool calls. Darren calls that completely flawed, because the loop itself directs code that holds secrets and talks to external systems. His answer: put the agent and its tools in one sandbox, with one policy for secrets and egress. Darren is on X and GitHub at @ibuildthecloud. https://obot.ai/ Where does your boundary sit: around the agent itself, or only around the tools it calls?





