Skip to solution
hardAI Engineering

How do you sandbox an agent and enforce least-privilege tool access?

1.2k views
01

Understand the problem

Blast-radius engineering: scoped credentials, allowlists, dry-runs and irreversibility gates.

sandboxingleast-privilegesecurityagents
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Nudge consolestandby

Stuck? Beam a request up — the console returns a conceptual nudge that guides your logic without spoiling the implementation.

03

Study the solution

Assume the agent can be wrong or hijacked, and bound the damage: give tools scoped, short-lived credentials (not admin keys); run code-executing tools in isolated sandboxes (containers, no network by default); allowlist file paths, hosts and commands; make destructive operations dry-run by default; and distinguish read

Solution ready — 2 min read

Classified // press E to declassify

04

Read the code

Tool registry with permission tiers
const registry: ToolPolicy[] = [
  { tool: readFile,     tier: "read",  scope: { paths: ["/workspace/**"] } },
  { tool: runTests,     tier: "read",  sandbox: { net: "none", cpuMs: 60_000 } },
  { tool: writeFile,    tier: "write", scope: { paths: ["/workspace/**"] } },
  { tool: gitPush,      tier: "irreversible" },        // human approval
  { tool: sendEmail,    tier: "irreversible" },
];

async function authorize(call: ToolCall, session: Session) {
  const p = registry.find((r) => r.tool.name === call.name);
  if (!p) throw deny("unknown tool");
  if (!inScope(call.input, p.scope)) throw deny("out of scope");
  if (p.tier === "irreversible") await requireHumanApproval(call, session);
}
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.

Transmission complete // awaiting log

KEEP THE
STREAK ALIVE.

Dossier 60 of 80 decoded in the AI Engineering track. One more won't hurt.

Back to track