zlacker

[return to "Sandboxing AI Agents in Linux"]
1. ATechG+dC[view] [source] 2026-02-03 20:05:50
>>speckx+(OP)
I will ask what I've asked before: how to know what resources to make available to agents and what policies to enforce? The agent behavior is not predefined; it may need access to a number of files & web domains.

For example, you said: > I don't expose entire /etc, just the bare minimum How is "bare minimum" defined?

> Inspecting the log you can spot which files are needed and bind them as needed. This requires manual inspection.

◧◩
2. aflag+JF[view] [source] 2026-02-03 20:21:40
>>ATechG+dC
Ask the agent to bubblewrap itself
[go to top]