From 627d485fbf2bb08d3a8d34182d4aded81bb06bd6 Mon Sep 17 00:00:00 2001 From: Ertug Karamatli <107676+ertug@users.noreply.github.com> Date: Mon, 27 Jul 2026 16:21:54 +0000 Subject: [PATCH 1/3] docs: note container isolation limits, add Jailbox reference --- the-security-guide.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/the-security-guide.md b/the-security-guide.md index d0a605bf2..4b9ad90a8 100644 --- a/the-security-guide.md +++ b/the-security-guide.md @@ -163,6 +163,10 @@ docker run -it --rm \ No network. No access outside `/workspace`. Much better failure mode. +Three limits worth naming. A container shares the host kernel, so it's a weaker boundary than hardware virtualization. The agent can sit inside the container, as it does above, while the editor you open the repo with does not: the 2025 Amazon Q Developer incident put a malicious payload into a VS Code extension update, landing on the developer's machine outside anything a container was wrapping. And `internal: true` is the right default, but the agent needs its model API, package registries, and git remotes, so you open a route out on day one. + +The path of least resistance is to open all of it. A narrower version is a VM that holds the editor and its extensions alongside the agent, reaches the internet, and has no route to the host, the LAN, or any private address. See [Jailbox](https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-agents/). + ### Restrict tools and paths This is the boring part people skip. It is also one of the highest leverage controls, literally maxxed out ROI on this because its so easy to do. @@ -442,6 +446,7 @@ Scan your setup: [github.com/affaan-m/agentshield](https://github.com/affaan-m/a - Hunt.io, "CVE-2026-25253 OpenClaw AI Agent Exposure" (February 3, 2026): [hunt.io](https://hunt.io/blog/cve-2026-25253-openclaw-ai-agent-exposure) - OpenAI, "Designing AI agents to resist prompt injection" (March 11, 2026): [openai.com](https://openai.com/index/designing-agents-to-resist-prompt-injection/) - OpenAI Codex docs, "Agent network access": [platform.openai.com](https://platform.openai.com/docs/codex/agent-network) +- Jailbox (hardened KVM sandbox VMs for agents and untrusted code: internet egress allowed, host/LAN/private addresses blocked): [karamatli.com](https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-agents/) --- From 907508e2072ec748c631203aa39c9b388cf714c5 Mon Sep 17 00:00:00 2001 From: haelyra <49814733+haelyra@users.noreply.github.com> Date: Tue, 11 Aug 2026 13:32:10 -0400 Subject: [PATCH 2/3] docs: qualify sandbox incident and reference --- the-security-guide.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/the-security-guide.md b/the-security-guide.md index 4b9ad90a8..58e27747c 100644 --- a/the-security-guide.md +++ b/the-security-guide.md @@ -163,9 +163,9 @@ docker run -it --rm \ No network. No access outside `/workspace`. Much better failure mode. -Three limits worth naming. A container shares the host kernel, so it's a weaker boundary than hardware virtualization. The agent can sit inside the container, as it does above, while the editor you open the repo with does not: the 2025 Amazon Q Developer incident put a malicious payload into a VS Code extension update, landing on the developer's machine outside anything a container was wrapping. And `internal: true` is the right default, but the agent needs its model API, package registries, and git remotes, so you open a route out on day one. +Three limits are worth naming. A container shares the host kernel, so it is a weaker boundary than hardware virtualization. The agent can sit inside the container, as it does above, while the editor you open the repo with does not. In 2025, malicious code reached version 1.84.0 of the Amazon Q Developer VS Code extension, although AWS reports that a syntax error prevented it from executing. A container around the agent would not have isolated an editor extension running on the host. And `internal: true` is the right default, but the agent needs its model API, package registries, and git remotes, so you open a route out on day one. -The path of least resistance is to open all of it. A narrower version is a VM that holds the editor and its extensions alongside the agent, reaches the internet, and has no route to the host, the LAN, or any private address. See [Jailbox](https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-agents/). +The path of least resistance is to open all of it. A narrower version is a VM that holds the editor and its extensions alongside the agent, reaches the internet, and has no route to the host, the LAN, or any private address. [Jailbox](https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-agents/) is one concrete KVM-based reference architecture for that pattern. ### Restrict tools and paths @@ -446,6 +446,7 @@ Scan your setup: [github.com/affaan-m/agentshield](https://github.com/affaan-m/a - Hunt.io, "CVE-2026-25253 OpenClaw AI Agent Exposure" (February 3, 2026): [hunt.io](https://hunt.io/blog/cve-2026-25253-openclaw-ai-agent-exposure) - OpenAI, "Designing AI agents to resist prompt injection" (March 11, 2026): [openai.com](https://openai.com/index/designing-agents-to-resist-prompt-injection/) - OpenAI Codex docs, "Agent network access": [platform.openai.com](https://platform.openai.com/docs/codex/agent-network) +- AWS, "Security Update for Amazon Q Developer Extension for Visual Studio Code (Version #1.84)": [aws.amazon.com](https://aws.amazon.com/security/security-bulletins/AWS-2025-015/) - Jailbox (hardened KVM sandbox VMs for agents and untrusted code: internet egress allowed, host/LAN/private addresses blocked): [karamatli.com](https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-agents/) --- From 3b5105816c94cce87b1a22183a7ab13d137bf087 Mon Sep 17 00:00:00 2001 From: haelyra <49814733+haelyra@users.noreply.github.com> Date: Fri, 28 Aug 2026 21:11:06 -0400 Subject: [PATCH 3/3] docs: constrain sandbox egress guidance Clarify the editor boundary, require deliberately bounded egress, qualify Jailbox as one verified reference pattern, and remove the duplicate AWS bulletin citation. --- the-security-guide.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/the-security-guide.md b/the-security-guide.md index 58e27747c..48429633f 100644 --- a/the-security-guide.md +++ b/the-security-guide.md @@ -163,9 +163,11 @@ docker run -it --rm \ No network. No access outside `/workspace`. Much better failure mode. -Three limits are worth naming. A container shares the host kernel, so it is a weaker boundary than hardware virtualization. The agent can sit inside the container, as it does above, while the editor you open the repo with does not. In 2025, malicious code reached version 1.84.0 of the Amazon Q Developer VS Code extension, although AWS reports that a syntax error prevented it from executing. A container around the agent would not have isolated an editor extension running on the host. And `internal: true` is the right default, but the agent needs its model API, package registries, and git remotes, so you open a route out on day one. +Three limits are worth naming. A container shares the host kernel, so it is a weaker boundary than hardware virtualization. It also protects only what actually runs inside it: with VS Code remote development, workspace extensions may run in the remote environment while UI extensions remain local. In 2025, malicious code reached version 1.84.0 of the Amazon Q Developer VS Code extension, although AWS reports that a syntax error prevented it from executing. A container around the agent would not have isolated an editor extension running on the host. -The path of least resistance is to open all of it. A narrower version is a VM that holds the editor and its extensions alongside the agent, reaches the internet, and has no route to the host, the LAN, or any private address. [Jailbox](https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-agents/) is one concrete KVM-based reference architecture for that pattern. +Keep `internal: true` when the work can stay offline. When model APIs, package registries, or git remotes require network access, add only a deliberately constrained egress path. Allowlist the required destinations or proxy them, block host, LAN, private, link-local, and metadata ranges, and verify the boundary from inside the sandbox. Attaching a general-purpose network restores broader reachability and should be an explicit exception. + +A stronger version is a VM that holds the editor and its extensions alongside the agent, reaches the internet through a verified policy, and has no route to the host, the LAN, or other private addresses. [Jailbox](https://karamatli.com/posts/network-isolated-kvm-sandbox-ai-agents/) is one concrete KVM-based reference architecture for that pattern; its default rules block private destinations and support narrowly scoped exceptions, so the effective configuration still needs verification. ### Restrict tools and paths @@ -436,7 +438,6 @@ Scan your setup: [github.com/affaan-m/agentshield](https://github.com/affaan-m/a - GitHub Docs, "Responsible use of Copilot coding agent on GitHub.com": [docs.github.com](https://docs.github.com/en/copilot/responsible-use-of-github-copilot-features/responsible-use-of-copilot-coding-agent-on-githubcom) - GitHub Docs, "Customize the agent firewall": [docs.github.com](https://docs.github.com/en/copilot/how-tos/use-copilot-agents/coding-agent/customize-the-agent-firewall) - Simon Willison prompt injection series / lethal trifecta framing: [simonwillison.net](https://simonwillison.net/series/prompt-injection/) -- AWS Security Bulletin, AWS-2025-015: [aws.amazon.com](https://aws.amazon.com/security/security-bulletins/rss/aws-2025-015/) - AWS Security Bulletin, AWS-2025-016: [aws.amazon.com](https://aws.amazon.com/security/security-bulletins/aws-2025-016/) - Unit 42, "Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild" (March 3, 2026): [unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/) - Microsoft Security, "AI Recommendation Poisoning" (February 10, 2026): [microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/10/ai-recommendation-poisoning/)