{"schema_version":"newruntime-agent-readable-v0.2","type":"post","stable_id":"post:anthropic-agent-containment-blast-radius","slug":"anthropic-agent-containment-blast-radius","title":"Containment Caps An Agent's Blast Radius","description":"Anthropic's three runtime patterns show why hard filesystem, network, credential, and trust boundaries carry more security weight than repeated approval prompts.","retrieval_nugget":"Anthropic's three runtime patterns show why hard filesystem, network, credential, and trust boundaries carry more security weight than repeated approval prompts. As agents gain access to shells, files, services, and credentials, risk is no longer captured by model behavior alone. Anthropic frames it as the combination of failure probability and blast radius.","status":"published","published_at":"2026-08-03","updated_at":"2026-08-03","record_date":"2026-08-03","date_kind":"published_at","topics":["agent-security","agent-harnesses","runtime-isolation","governance"],"source_urls":["https://www.anthropic.com/engineering/how-we-contain-claude"],"visuals":[{"id":"anthropic-agent-containment-blast-radius","kind":"editorial-diagram","role":"hero","src":"https://newruntime.com/images/posts/anthropic-agent-containment-blast-radius.webp","alt":"Hand-drawn comparison of an ephemeral server container, an operating-system coding sandbox, and a local virtual machine, each limiting the files, credentials, and network actions an agent can reach.","caption":"Containment limits what an agent can reach even when a user, model, or attacker gets the intended behavior wrong.","credit":"New Runtime synthesis from Anthropic","source_url":"https://www.anthropic.com/engineering/how-we-contain-claude","generated_with":"gemini-3.1-flash-image","width":1600,"height":900,"legend":[{"label":"Ephemeral container","description":"Server-side code execution gets a small blast radius but no persistent local workspace."},{"label":"OS sandbox","description":"Coding work can write inside the project while network access stays denied by default."},{"label":"Local VM","description":"Knowledge work sees only mounted folders while host credentials remain outside the guest."},{"label":"Capability boundary","description":"Allowed domains, mounts, and connectors grant capabilities rather than merely naming destinations."}]}],"routes":{"html":"https://newruntime.com/posts/anthropic-agent-containment-blast-radius/","markdown":"https://newruntime.com/posts/anthropic-agent-containment-blast-radius.md","json":"https://newruntime.com/posts/anthropic-agent-containment-blast-radius.json"},"source_format":"markdown","next_reads":[{"type":"topic","path":"/topics/agent-security/","reason":"Explore the agent security topic hub.","url":"https://newruntime.com/topics/agent-security/","title":"Agent Security - New Runtime","media_type":"text/html"},{"type":"topic","path":"/topics/governance/","reason":"Explore the governance topic hub.","url":"https://newruntime.com/topics/governance/","title":"Governance - New Runtime","media_type":"text/html"},{"type":"related_material","path":"/posts/claude-code-auto-mode-action-gate/","reason":"Shares agent harnesses and agent security.","url":"https://newruntime.com/posts/claude-code-auto-mode-action-gate/","title":"Claude Code Auto Mode Gates Actions Instead Of Explanations","media_type":"text/html"},{"type":"related_material","path":"/posts/open-secure-ai-alliance-open-defense-stack/","reason":"Shares agent harnesses and governance.","url":"https://newruntime.com/posts/open-secure-ai-alliance-open-defense-stack/","title":"Open Secure AI Alliance Turns the AI-Safety Fight Into a Stack Question","media_type":"text/html"},{"type":"related_material","path":"/posts/agentic-sdlc-software-factory-loop/","reason":"Shares agent harnesses.","url":"https://newruntime.com/posts/agentic-sdlc-software-factory-loop/","title":"A Software Factory Connects Agents Through Verified Outcomes","media_type":"text/html"}]}
