• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
  • HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    AI

    Santiago Valdarrama Urges Isolated Environments for AI Agents

    Post shares hard lessons from code execution mishaps and recommends sandboxing.

    SA
    2 Sources, 28d ago, first seen 28d ago

    TLDR

    Santiago Valdarrama posted that any agent executing code must run inside an isolated environment. He stated he learned this the hard way and knows others whose laptops had to be wiped after OpenClaw went out of control. The post lists two rules: agents that run code require isolation, and he attached a link to the CubeSandbox GitHub repository, described there as an instant, concurrent, secure and lightweight sandbox for AI agents from TencentCloud.

    Combined views

    16K

    2 Sources, first seen 28d ago

    Combined views

    16K

    2 Sources, first seen 28d ago

    211 likes
    211 likes
    26 comments
    280 saves
    35 reposts

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    26 comments
    280 saves
    35 reposts
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet

    Sentiment

    Positive——Negative

    Summary

    Not enough discussion yet.

    No sentiment analysis available yet.

    2 Sources

    @svpinoIf your agent executes code, you want to run it in an isolated environment. I learned this the hard way. I also know a couple of people who let OpenClaw go nuts and had to wipe out their laptops after a few days to clean up the mess. Two rules you must always follow: 1. Agent that runs code → isolated environment 2. Agent that controls a browser → isolated environment But that generates a new problem: that environment has to start quickly, use as little memory as possible, and give you enough control to operate it. This is hard to achieve, but you don't need to reinvent the wheel: Cube Sandbox is an open-source MicroVM sandbox developed by Tencent Cloud. Think of it as a production-grade agent infrastructure that you can use to run agents at scale. Cube Sandbox uses RustVMM and KVM to run each sandbox with hardware-level isolation. • It cold-starts in under 60ms • It uses less than 5MB of RAM overhead • You can launch tens of thousands of sandboxes within a minute Here is what you can do with it: 1. Capture, clone, and restore sandbox state with snapshots and rollback 2. Deploy sandbox clusters through Kubernetes 3. Run workloads on ARM infrastructure 4. Observe what happens inside agent executions 5. Govern ingress and egress traffic 6. Persistent volumes and cross-machine pause/resume Here is the GitHub repository: https://github.com/TencentCloud/CubeSandbox You can inspect the code and try it out with your own agent workflow. #ad

    2 Sources

    @svpinoIf your agent executes code, you want to run it in an isolated environment. I learned this the hard way. I also know a couple of people who let OpenClaw go nuts and had to wipe out their laptops after a few days to clean up the mess. Two rules you must always follow: 1. Agent that runs code → isolated environment 2. Agent that controls a browser → isolated environment But that generates a new problem: that environment has to start quickly, use as little memory as possible, and give you enough control to operate it. This is hard to achieve, but you don't need to reinvent the wheel: Cube Sandbox is an open-source MicroVM sandbox developed by Tencent Cloud. Think of it as a production-grade agent infrastructure that you can use to run agents at scale. Cube Sandbox uses RustVMM and KVM to run each sandbox with hardware-level isolation. • It cold-starts in under 60ms • It uses less than 5MB of RAM overhead • You can launch tens of thousands of sandboxes within a minute Here is what you can do with it: 1. Capture, clone, and restore sandbox state with snapshots and rollback 2. Deploy sandbox clusters through Kubernetes 3. Run workloads on ARM infrastructure 4. Observe what happens inside agent executions 5. Govern ingress and egress traffic 6. Persistent volumes and cross-machine pause/resume Here is the GitHub repository: https://github.com/TencentCloud/CubeSandbox You can inspect the code and try it out with your own agent workflow. #ad