Kimi's paper underlines the importance of the right security boundary for agents to run in.
tl:DR: container-level isolation is not enough. In their experiments, agents crashed the underlying machine (via kernel panics).
Firecracker microVMs (as in Vercel Sandbox) are safe.
Kimi's paper underlines the importance of the right security boundary for agents to run in.
tl:DR: container-level isolation is not enough. In their experiments, agents crashed the underlying machine (via kernel panics).
Firecracker microVMs (as in Vercel Sandbox) are safe.