|
|
|
|
|
by chaosprint
92 days ago
|
|
"The stronger boundary protects the machine while the agent is coding, testing and improvising. It does not protect the rest of the world from the permissions you have already granted. A better-isolated runtime will not stop the bot from spraying outbound messages, sending a stupid email, or otherwise turning your authority into a minor public nuisance." from: https://entropytown.com/articles/2026-03-12-openclaw-sandbox... plus, any idea why not podman or firecracker? |
|
Regarding security, I think you need three things:
I'm working on a product that makes it as easy to spin up remote agent sandboxes as it is to git push and git pull. Then when we get that working well we're putting a proxy around each sandbox to let users control filtering rules.I personally see a future where there are many different types of *Claws, coding agents, etc. and I think they need a new "operating system", so to speak.
Self-plug at the end: https://github.com/gofixpoint/amika. The OSS part of my startup, focused on sandbox coding agents right now :)
PS: I enjoyed the entropytown.com blog! bookmarking it