CVE Tools

Полезайте в песочницу, мистер Claude: изолируем агента

Хабр — Информационная безопасностьBy Andrew42

Research

Our summary

The article describes using Docker Sandbox (CLI: sbx) to run AI agents such as Claude Code inside a microVM, so the agent cannot directly access host secrets like OAuth tokens, SSH keys, or GitHub PATs. It highlights key isolation properties—separate microVM kernel, no access to host Docker daemon/socket, workspace-only filesystem exposure, and network restrictions that force outbound traffic through a host-side proxy—making accidental destructive actions or token theft less likely. No specific CVE identifiers are mentioned, but the core message is that stronger isolation at runtime matters when agents run with the permissions of the user who launched them.

Read at Хабр — Информационная безопасность

Хабр — Информационная безопасность publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store