logoalt Hacker News

mintflow • today at 11:30 AM • 4 replies • view on HN

Seems aws also announced a sandbox solution

I used agent over 1 year and basically always give codex full permission on each thread, do not get issue so far

Why we need this layer of complexity? Or its mainly for big company that need control ?


Replies

hedgehog • today at 6:08 PM

It's very useful to ensure that code under test has limited access to resources both to avoid making a mess outside the intended workspace. Otherwise there's risk of deleting or killing stuff it shouldn't, or just using too much memory or CPU and causing OOM kill or other issues. If a runaway command turns into a nice error for the agent then it becomes something that will self-resolve without fuss.

pprotas • today at 12:58 PM

The main usecase for an average developer is preventing confused agents making mistakes like removing sensitive folders, resetting git branches or using API tokens they shouldn't be using

dannyw • today at 1:16 PM

A ~month ago, auto-review (rightfully) blocked a rm that would've nuked my home directory, due to shell mangling (amongst other issues).

joshuanapoli • today at 11:36 AM

If you have a custom agent in a product, then it needs isolation to be sure to protect the customer data.

➕ show 1 reply