Blast-radius engineering: scoped credentials, allowlists, dry-runs and irreversibility gates.
Skip to solutionKEEP THE
hardAI Engineering
How do you sandbox an agent and enforce least-privilege tool access?
1.2k views
01
Understand the problem
sandboxingleast-privilegesecurityagents
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Nudge consolestandby
Stuck? Beam a request up — the console returns a conceptual nudge that guides your logic without spoiling the implementation.
03
Study the solution
Assume the agent can be wrong or hijacked, and bound the damage: give tools scoped, short-lived credentials (not admin keys); run code-executing tools in isolated sandboxes (containers, no network by default); allowlist file paths, hosts and commands; make destructive operations dry-run by default; and distinguish read
Solution ready — 2 min read
Classified // press E to declassify
04
Read the code
Tool registry with permission tiers
const registry: ToolPolicy[] = [
{ tool: readFile, tier: "read", scope: { paths: ["/workspace/**"] } },
{ tool: runTests, tier: "read", sandbox: { net: "none", cpuMs: 60_000 } },
{ tool: writeFile, tier: "write", scope: { paths: ["/workspace/**"] } },
{ tool: gitPush, tier: "irreversible" }, // human approval
{ tool: sendEmail, tier: "irreversible" },
];
async function authorize(call: ToolCall, session: Session) {
const p = registry.find((r) => r.tool.name === call.name);
if (!p) throw deny("unknown tool");
if (!inScope(call.input, p.scope)) throw deny("out of scope");
if (p.tier === "irreversible") await requireHumanApproval(call, session);
}05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.
Transmission complete // awaiting log
KEEP THE
STREAK ALIVE.
Dossier 60 of 80 decoded in the AI Engineering track. One more won't hurt.