<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sandbox on François Duthilleul</title><link>https://fduthilleul.eu/tags/sandbox/</link><description>Recent content in Sandbox on François Duthilleul</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François Duthilleul</copyright><atom:link href="https://fduthilleul.eu/tags/sandbox/index.xml" rel="self" type="application/rss+xml"/><item><title>OpenShell</title><link>https://fduthilleul.eu/security/openshell/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://fduthilleul.eu/security/openshell/</guid><description>&lt;p&gt;&lt;strong&gt;OpenShell&lt;/strong&gt; is an open-source runtime for fleets of autonomous AI agents. An agent is useful because it can read files, run commands, call APIs, and use credentials; that is also the capability profile of a compromised workload. OpenShell leaves the agent free to plan and use tools, and enforces what it may touch outside the model. Three pieces do the work: a &lt;strong&gt;gateway&lt;/strong&gt; manages sandboxes and their policies, a &lt;strong&gt;supervisor&lt;/strong&gt; sits outside the workload and inspects every outbound request, and the &lt;strong&gt;sandbox&lt;/strong&gt; confines the process with kernel controls — &lt;strong&gt;Landlock&lt;/strong&gt; on the filesystem, &lt;strong&gt;seccomp&lt;/strong&gt; on system calls, and user and network namespaces — so the only network path is through the supervisor. Credentials stay outside the agent and are attached only to requests bound for an approved endpoint. Policy is written in YAML, compiled to OPA/Rego, and checked by a prover before a change is applied, so a requested permission can be shown to cross a boundary even if the agent argues that it does not. Denials come back as structured &lt;strong&gt;OCSF&lt;/strong&gt; events rather than silent failures. Prompt guardrails still matter, but they are not the boundary: a model that has been talked into misbehaving keeps whatever credentials it was given unless the runtime never put them there.&lt;/p&gt;</description></item></channel></rss>