Agents & tools · Glossary term
What is Sandbox?
An isolated execution environment that restricts an agent's access to files, processes, network destinations, credentials, and host resources.
Why does Sandbox matter?
Generated code and tool calls can be wrong or malicious. Isolation limits their reach and makes disposable verification practical.
Sandbox in practice
Run tests in an ephemeral container with a read-only base, a scoped writable workspace, no production secrets, and an explicit network allowlist.
What is the common confusion about Sandbox?
A sandbox reduces impact. It does not establish that the code inside is correct or harmless.
Learn Sandbox in the course
Start with
- Production Runtimes: Queue, Event, Cron
Production agents run on six runtime shapes: request-response, streaming, durable execution, queue-based background, event-driven, and scheduled. Pick the shape before you pick the framework.
Lessons that name Sandbox in a title or section
- Skill Permissions, Sandboxes, and Trust
A skill can suggest an action. Only the host can authorize it, only an isolation boundary can contain it, and only verification can tell you whether it worked.
- Capstone Lesson 26: Sandbox Runner with Denylist and Path Jail
The verification gate decides whether a tool call should run. The sandbox decides what happens when it does. This lesson ships a subprocess runner that refuses dangerous executables, refuses…
- MCP Apps on the Stateless Protocol
An interactive result is still an MCP tool and resource exchange. The 2026-07-28 core makes that exchange self-contained, while the Apps extension adds the sandboxed browser surface.
Taught in Phase 14: Agent Engineering.
Also covered in Phase 13: Tools & Protocols and Phase 19: Capstone Projects.
Related terms
- Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
- Approval GateA control point that blocks a consequential action until an authorized person or policy grants permission.
- Coding AgentAn agent specialized for software work that can inspect a repository, edit files, run development tools, and use their outputs to advance…
- GuardrailsSystem controls that constrain inputs, tool use, outputs, permissions, and escalation.
- Agent HarnessThe runtime around a model that assembles context, exposes tools, manages state, enforces limits, records traces, and decides when the…
- Defense in DepthUsing independent preventive, detective, and corrective controls at several system boundaries so one failed control does not determine the…
- Prompt InjectionAn attack or failure mode in which untrusted content influences a model to disregard intended instructions, expose data, misuse tools, or…
- Skill InvocationThe runtime-mediated process in which an eligible human, model, application, or other skill selects a skill and causes its instructions to…
- Threat ModelA documented account of protected assets, trust boundaries, potential adversaries, assumed capabilities, attack paths, impacts, and…
- Trust BoundaryAn interface where data, instructions, identity, or authority crosses between components or principals that operate under different trust…
More terms in Agents & tools
- Agent
- Agent Harness
- Agent Memory
- Agent State
- Agent Skill
- Approval Gate
- Checkpoint
- Compensating Action
- Delegation
- Durable Execution
- Function Calling
- Human-in-the-Loop (HITL)
- MCP (Model Context Protocol)
- Multi Round-Trip Request (MRTR)
- Orchestration
- Planning
- ReAct
- Skill Bundle
- Skill Catalog
- Skill Discovery
- Skill Invocation
- Stateless MCP
- Structured Output
- Swarm
- Termination Condition
- Tool Contract
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.