Agents & tools · Glossary term

What is Sandbox?

An isolated execution environment that restricts an agent's access to files, processes, network destinations, credentials, and host resources.

Why does Sandbox matter?

Generated code and tool calls can be wrong or malicious. Isolation limits their reach and makes disposable verification practical.

Sandbox in practice

Run tests in an ephemeral container with a read-only base, a scoped writable workspace, no production secrets, and an explicit network allowlist.

What is the common confusion about Sandbox?

A sandbox reduces impact. It does not establish that the code inside is correct or harmless.

Learn Sandbox in the course

Start with

  • Production Runtimes: Queue, Event, Cron

    Production agents run on six runtime shapes: request-response, streaming, durable execution, queue-based background, event-driven, and scheduled. Pick the shape before you pick the framework.

    Phase 14: Agent Engineering

Lessons that name Sandbox in a title or section

  • Skill Permissions, Sandboxes, and Trust

    A skill can suggest an action. Only the host can authorize it, only an isolation boundary can contain it, and only verification can tell you whether it worked.

    Phase 13: Tools & Protocols

  • Capstone Lesson 26: Sandbox Runner with Denylist and Path Jail

    The verification gate decides whether a tool call should run. The sandbox decides what happens when it does. This lesson ships a subprocess runner that refuses dangerous executables, refuses…

    Phase 19: Capstone Projects

  • MCP Apps on the Stateless Protocol

    An interactive result is still an MCP tool and resource exchange. The 2026-07-28 core makes that exchange self-contained, while the Apps extension adds the sandboxed browser surface.

    Phase 13: Tools & Protocols

Taught in Phase 14: Agent Engineering.

Also covered in Phase 13: Tools & Protocols and Phase 19: Capstone Projects.

  • Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
  • Approval GateA control point that blocks a consequential action until an authorized person or policy grants permission.
  • Coding AgentAn agent specialized for software work that can inspect a repository, edit files, run development tools, and use their outputs to advance…
  • GuardrailsSystem controls that constrain inputs, tool use, outputs, permissions, and escalation.
  • Agent HarnessThe runtime around a model that assembles context, exposes tools, manages state, enforces limits, records traces, and decides when the…
  • Defense in DepthUsing independent preventive, detective, and corrective controls at several system boundaries so one failed control does not determine the…
  • Prompt InjectionAn attack or failure mode in which untrusted content influences a model to disregard intended instructions, expose data, misuse tools, or…
  • Skill InvocationThe runtime-mediated process in which an eligible human, model, application, or other skill selects a skill and causes its instructions to…
  • Threat ModelA documented account of protected assets, trust boundaries, potential adversaries, assumed capabilities, attack paths, impacts, and…
  • Trust BoundaryAn interface where data, instructions, identity, or authority crosses between components or principals that operate under different trust…

More terms in Agents & tools

Open the Agents & tools list in the glossary

This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.