Sandboxing & isolation

P59.agent-boundaries.02 · Audience: guest, it-ml, language-pro · Prerequisites: Tool & permission boundaries for agents

Real LLM grading for this pageLLM grading (this page):

An agent that writes and runs code must run it somewhere it cannot hurt anyone. The isolation floor is four properties: no network, a confined filesystem, and CPU and memory limits.

The worked example is the one you are standing in: this platform's practice sandbox (ADR-011) — namespaces, no network, a per-run temporary filesystem, metered resources. The same sandbox grades the exercises on this page. Escape classes exist (kernel bugs, misconfigured mounts), which is exactly why isolation is layered rather than trusted absolutely.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — check a sandbox policy meets the floor

Loading exercise…

My notes on this module

Loading your notes...

Sandboxing & isolation — TransformerLab