diff --git a/docs/research/agent-sandbox-landscape.md b/docs/research/agent-sandbox-landscape.md index 193cbfb..a23153a 100644 --- a/docs/research/agent-sandbox-landscape.md +++ b/docs/research/agent-sandbox-landscape.md @@ -97,7 +97,8 @@ claim that the monetization positioning leans on. See the addendum. ### agent-safehouse - **Source**: https://agent-safehouse.dev/ ; https://github.com/eugene1g/agent-safehouse -- **License**: Apache 2.0 (~1,400 stars) +- **HN launch**: [#47301085](https://news.ycombinator.com/item?id=47301085) (March 12 2026) — 823 points +- **License**: Apache 2.0 (~1,781 stars at launch) - **Isolation**: macOS `sandbox-exec` (Seatbelt) profiles — kernel-level syscall interception, no container. - **Locality**: Local, macOS only. @@ -107,6 +108,16 @@ claim that the monetization positioning leans on. See the addendum. - **Config**: Shell functions or custom `sandbox-exec` profile files; LLM-assisted profile generation supported. - **Network policy**: Not addressed. +- **Notable from HN thread**: Creator acknowledged the project is "just a + policy-generator for `sandbox-exec` — no dependencies, no daemons, no + subscription; I did put in many hours to identify the minimum required + permissions for agents to continue working." Simon Willison noted that + evaluating whether a sandboxing tool actually works as intended is hard. + Top community sentiment: *"I honestly think that sandboxing is currently + THE major challenge that needs to be solved for the tech to fully realise + its potential."* The macOS Docker gap (Docker for Mac runs inside a Linux + VM, so `sandbox-exec` is the only native primitive for bare-metal macOS + processes) was the stated motivation. - **Maturity**: Active through March 2026. ### matchlock @@ -372,7 +383,7 @@ them. | DX: run Claude yolo-style | One command → interactive yolo Claude (`start `, `--dangerously-skip-permissions` default) | n/a (lib demo) | Wizard + build, then run claude inside (Linux only) | One-command wrapper (`safehouse claude --dangerously-skip-permissions`) | CLI: run a cmd in a VM (not a Claude wrapper) | Hosted (`tilde exec`), not local-native | SDK code required (build the run yourself) | CLI/MCP: sandbox-as-a-tool for the agent, not a wrapper around it | SSH into a named machine, run claude there | Stand up a cluster + drive via E2B SDK | CI-oriented, not a Claude wrapper | MCP server: `claude mcp add container-use -- container-use stdio` | One command: `sbx` wraps claude with `--dangerously-skip-permissions` default | Library/wrapper, not a standalone CLI | | Config | JSON manifest (bottles + agents) | Programmatic refs | CLI wizard | Profile files / shell fns | CLI / SDK | DSL + CLI + SDK | SDK | CLI / SDK / MCP | TOML Smolfile | E2B-compatible SDK | cleanroom.yaml in repo | None (no policy config) | Preset levels at launch | Programmatic per-invocation (allow/deny lists) | | Agent-tailored policy | Yes — bottle/agent split; declarative per-role egress + credentials; composable via `extends:` | Partial — capability model scopes per-agent, but no declarative role manifest | No | Partial — per-agent profile files (Seatbelt); no egress | No | Yes — per-agent DSL RBAC (allow/deny/approve per action/repo/agent) | No | No | No | No — per-sandbox SDK config, not role-scoped | Partial — per-repo cleanroom.yaml, not per-role | No | No — network presets only | No | -| Maturity | Active July 2026 | Research (2022+) | Early (~66 ⭐) | Active (~1.4k ⭐) | Experimental (~574 ⭐) | Private preview | YC, ~4.7k ⭐ | YC, ~6k ⭐, beta | ~3.1k ⭐ | Tencent, prod, ~10.4k ⭐ | Active (Buildkite product) | Early development | GA 2026 | Early research preview | +| Maturity | Active July 2026 | Research (2022+) | Early (~66 ⭐) | Active (~1.8k ⭐) | Experimental (~574 ⭐) | Private preview | YC, ~4.7k ⭐ | YC, ~6k ⭐, beta | ~3.1k ⭐ | Tencent, prod, ~10.4k ⭐ | Active (Buildkite product) | Early development | GA 2026 | Early research preview | ## What's closest, what's different @@ -385,7 +396,9 @@ keeping Docker only as a legacy fallback; agent-safehouse uses `sandbox-exec`; litterbox uses Podman + Landlock. matchlock and smolmachines are close on *both* the policy side (default-deny net, per-host allowlist) and — now that bot-bottle has moved off -containers-by-default — the microVM isolation primitive. +containers-by-default — the microVM isolation primitive. Note: Apple +Container 1.0 stable shipped June 9 2026 (frozen CLI and APIs), which +makes the macOS backend stable surface area rather than a moving target. **New closest on agent-tailored policy.** Two governance tools are the direct competitors on the "coarse-grained sandbox" axis. **tilde.run** diff --git a/docs/research/hn-agent-safety-discourse-july-2026.md b/docs/research/hn-agent-safety-discourse-july-2026.md index 4e329d9..956f71c 100644 --- a/docs/research/hn-agent-safety-discourse-july-2026.md +++ b/docs/research/hn-agent-safety-discourse-july-2026.md @@ -43,6 +43,18 @@ surveyed what developers were actually deploying: "containers or YOLO" dominated. The honest community mood was that most teams hadn't solved this and were shipping anyway. +The March 12 launch of **Agent Safehouse** +([#47301085](https://news.ycombinator.com/item?id=47301085), 823 points) +crystallised the community framing: a zero-dep `sandbox-exec` wrapper for +macOS that attracted the top comment *"I honestly think that sandboxing is +currently THE major challenge that needs to be solved for the tech to fully +realise its potential."* The creator's own framing — "no dependencies, no +daemons, no subscription; the simplicity is the feature" — and Simon +Willison's observation that evaluating whether a sandboxing tool works as +intended is itself hard, both prefigure the June–July shift in tone. See +[`agent-sandbox-landscape.md`](agent-sandbox-landscape.md) for a full +per-project breakdown. + ## The June–July attack cascade Six attack patterns broke in quick succession. Together they form the