Agent Runtime Sandboxes & Code Execution

Parent: AI Agent Ecosystems · researched 2026-06-03T22:51:13.126Z· 27 sources · 12 concepts · skill agent-runtime-sandboxes

Secure, ephemeral cloud environments where an AI agent runs LLM-generated code, uses a computer,

Agent Runtime Sandboxes & Code Execution

When to use / Skip

Why agents need sandboxes

The managed-sandbox landscape

Tier 1 — full SDKs, build your patterns here

Tier 2 — concrete specifics, narrower fit

Tier 3 — built-in (lab-hosted) interpreters: zero infra, vendor's data plane

SDK patterns

Selection / decision guidance

Security model from the consumer side

Anti-patterns & failure modes

2025-2026 frontier

Sources

Children

Frontier under this node: Built-in vs standalone vs BYOC sandboxes, Code Mode / programmatic tool calling, Dual-LLM & CaMeL capability-based mitigation, Filesystem snapshots & declarative images, GPU sandboxes for ML agents, MCP-in-a-sandbox (gateways, credential brokering), MicroVM vs gVisor vs container isolation, Network egress policy (default-deny, allow-lists), Pause-resume & memory snapshots, Sandbox forking (copy-on-write branching), Sandbox lifecycle (create/exec/dispose), The lethal trifecta & prompt-injection exfiltration

← the whole tree · 3D view· how to read this page