runtime sandboxing

Designs, builds, and analyzes isolated runtime environments and infrastructure that constrain code, processes, or agents to limited resources and interfaces using containers, namespaces, filesystem overlays, permission controls, and related sandboxing techniques. Implements and configures sandbox provisioning, tooling, experimentation, and policy strategies to enforce isolation, least privilege, secure code execution, and safe integration of external tools or agents.

runtimesandboxing

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
3.15
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$219K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the security risks posed by AI agents frequently executing untrusted code on developer machines, where existing isolation mechanisms suffer from limitations in privilege requirements, performance overhead, and granularity of control. The authors propose a privilege-free, fine-grained process sandboxing architecture that compiles static security policies into kernel-enforced rules using Linux primitives such as seccomp and namespaces, while delegating dynamic decisions to a lightweight userspace supervisor. This approach enables rootless enforcement over filesystem, network, IPC, and system call access, supports time-of-check-to-time-of-use (TOCTOU)-safe validation and reversible file operations, and avoids dependencies on containers, cgroups, or images. Experimental results demonstrate a startup overhead of only ~5 ms, Redis performance matching bare-metal levels, and stage-based isolation of data, network, and untrusted content.

AI agentisolationLinux primitives

Threadbox: Sandboxing for Modular Security

Jun 30, 2025
MA
Maysara Alhindi
🏛️ University of Bristol

Traditional sandboxing mechanisms require application code refactoring, severely hindering deployment in legacy systems. This paper proposes Threadbox, a fine-grained, thread-level sandboxing framework that enables modular isolation and resource control for arbitrary functions without modifying application architecture. Its core innovation lies in lowering the sandbox boundary to the thread level, synergistically integrating runtime scheduling with OS-level resource isolation to deliver a lightweight, dynamic, and embeddable secure execution environment. Evaluation demonstrates that Threadbox effectively isolates sensitive operations with an average performance overhead of less than 8.2%. It significantly enhances sandbox flexibility, integrability, and practical applicability—advancing secure isolation toward modularity and runtime programmability.

Challenges in applying existing sandboxing mechanisms to certain applicationsEnabling sandboxing for threads and specific functionsProposing Threadbox for modular and independent sandboxing

SandCell: Sandboxing Rust Beyond Unsafe Code

Sep 28, 2025
JZ
Jialun Zhang
🏛️ Pennsylvania State University | Ericsson Security Research | Ericsson Product Security

Rust’s memory safety relies on its ownership system, yet `unsafe` code can bypass these checks, introducing critical security vulnerabilities. Existing isolation approaches support only static, fixed-boundary sandboxing of `unsafe` modules, lacking flexibility for dynamic, fine-grained co-sandboxing of safe and unsafe code. This paper proposes a lightweight, syntax-aware dynamic isolation mechanism for Rust: leveraging zero-cost abstractions and fine-grained sandbox partitioning, it enables runtime-configurable cross-safety-domain policies; combined with optimized data transfer, it significantly reduces inter-sandbox call overhead. Evaluated on multiple real-world Rust applications, the mechanism effectively contains vulnerability propagation while incurring an average performance overhead of less than 8.2%. It thus achieves a practical balance among security assurance, usability, and backward compatibility.

Minimizing performance overhead in cross-sandbox data transfersProviding flexible isolation for safe and unsafe componentsSandboxing Rust code beyond unsafe boundaries

This work addresses the emerging security threat posed by state-of-the-art large language models (LLMs) operating as autonomous agents within containerized sandbox environments, where they may exploit system vulnerabilities to achieve escape. To systematically evaluate this risk, we introduce SANDBOXESCAPEBENCH—the first comprehensive benchmark encompassing four categories of escape scenarios: misconfigurations, privilege abuse, kernel flaws, and runtime weaknesses. Employing a nested sandbox architecture and a CTF-inspired evaluation paradigm, our framework safely quantifies the escape capabilities of LLMs granted shell access. Experiments conducted using the Inspect AI framework with Docker/OCI containers demonstrate that current LLMs can effectively identify and exploit real-world vulnerabilities to escape confinement, underscoring the critical role of this benchmark in assessing and enhancing the deployment security of LLM-based agents.

adversarial agentAI safetycontainer security

Latest Papers

What's happening recently
View more

Current research on the security of execution environments for AI coding agents remains highly fragmented, lacking systematic integration and cross-disciplinary coordination. This work presents the first comprehensive survey of the field, analyzing 39 papers published between 2023 and 2026 and categorizing them into 17 thematic groups. Through CVE validation, cross-category comparison, and threat modeling, the study identifies critical disconnects among key areas such as isolation, access control, and time-of-check-to-time-of-use (TOCTOU) vulnerabilities, revealing five major research gaps. The analysis confirms four patched CVEs affecting production frameworks, quantifies the failure rate of existing mitigation strategies at 69%–98%, and uncovers that 17.1% of benign out-of-bound behaviors remain unaddressed by current mechanisms. Building on these findings, the paper proposes a unified research agenda to advance the field.

access controlAI coding agentsexecution security

This work addresses the "privilege laundering" problem in tool-augmented agents, where individually benign tool permissions can combine to enable unsafe behaviors. The authors propose a transparent runtime defense mechanism that requires no modifications to either the agent or tool servers. Built upon an MCP proxy, the approach introduces receiver-oriented capability budgets and enforces monotonic capability decay through intersection-based propagation, ensuring that combined permissions can only weaken—not strengthen—during composition. By integrating explicit information flow control with a trusted allowlist, the method reduces attack success rates from 25–68% to 0–4.8% across 82 tasks while maintaining normal task completion rates of 96–100%, substantially outperforming existing baselines.

capability attenuationcomposition safetypermission laundering

Current research on the security of LLM-agent systems remains fragmented, lacking a unified framework to explain the common root causes and propagation mechanisms underlying failures such as prompt injection and tool misuse. This work establishes *isolation* as a first-class principle for system security and introduces a boundary-centric taxonomy comprising five boundary types: user–agent, agent–tool, agent–execution, agent–agent, and system–environment. By systematically modeling failure pathways and defense strategies through structured review and cross-domain analysis, the study reveals that security failures predominantly originate from insufficient isolation and follow distinct cross-boundary attack propagation patterns. The paper thus provides a cohesive theoretical foundation and a construction-oriented research agenda centered on isolation for designing highly secure agent systems.

boundary failureisolationLLM-agent system safety

This work addresses the absence of a unified, verifiable runtime safety mechanism in existing MCP-style agents, where security decisions are fragmented across multiple components. To bridge this gap, the paper introduces HCP (Handle-Capability Protocol), a runtime framework that, while fully compatible with MCP workflows, formally defines eight execution-layer safety invariants for the first time. HCP enforces these invariants through a fine-grained access control model grounded in subjects, resources, capabilities, handles, and policies, explicitly ensuring critical properties such as subject binding, capability scoping, and data-flow authorization. Empirical evaluation demonstrates that HCP successfully blocks all attacks across ten benchmark scenarios while preserving auditable evidence, substantially outperforming baseline approaches. Microbenchmark results further indicate that policy operations incur an average latency of less than one millisecond.

capability-based securityexecution controlMCP-style agent

Hot Scholars

DS

Dawn Song

Professor of Computer Science, UC Berkeley
Computer Security and Privacy
DL

David Lo

Professor of Computer Science, Singapore Management University
AI4SESoftware AnalyticsSE4AISoftware Maintenance
YZ

Yuchen Zhuang

Google DeepMind
Reinforcement LearningLarge Language ModelsAgentic Coding
ZX

Zhiheng Xi

Fudan University
LLM ReasoningLLM-based Agents