{"schema_version":"newruntime-topic-hub-v0.2","type":"topic_hub","stable_id":"topic_hub:sandbox","slug":"sandbox","title":"Sandbox - New Runtime","description":"A New Runtime topic hub collecting signals, patterns, field notes, and public sources about sandbox.","retrieval_nugget":"A New Runtime topic hub collecting signals, patterns, field notes, and public sources about sandbox. Sandbox is tracked here as an evidence-linked topic, not as a static glossary entry. The page connects raw observations to pattern hypotheses, longer analysis, and public sources. Use it as the canonical landing page before drilling into individual records.","answer":["Sandbox is tracked here as an evidence-linked topic, not as a static glossary entry.","The page connects raw observations to pattern hypotheses, longer analysis, and public sources.","Use it as the canonical landing page before drilling into individual records."],"search_intents":["sandbox","sandbox AI agents","sandbox software"],"status":"featured","last_updated":"2026-07-24","record_date":"2026-07-24","date_kind":"last_updated","counts":{"total":29,"signals":26,"patterns":1,"posts":2,"atlas":0,"sources":37},"routes":{"html":"https://newruntime.com/topics/sandbox/","markdown":"https://newruntime.com/topics/sandbox.md","json":"https://newruntime.com/topics/sandbox.json"},"source_urls":["https://agentos-sdk.dev/","https://aitmpl.com/component/hook/dangerous-command-blocker","https://anthropic.com/engineering/claude-code-auto-mode","https://anthropic.com/glasswing","https://blog.cloudflare.com/moltworker-self-hosted-ai-agent","https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms","https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240","https://claude.com/blog/building-with-claude-managed-agents","https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks","https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent","https://docs.clawd.bot/gateway/security","https://docs.sprites.dev/"],"top_sources":["https://agentos-sdk.dev/","https://aitmpl.com/component/hook/dangerous-command-blocker","https://anthropic.com/engineering/claude-code-auto-mode","https://anthropic.com/glasswing","https://blog.cloudflare.com/moltworker-self-hosted-ai-agent","https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms","https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240","https://claude.com/blog/building-with-claude-managed-agents","https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks","https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent","https://docs.clawd.bot/gateway/security","https://docs.sprites.dev/"],"evidence_records":[{"kind":"Pattern","stable_id":"pattern:agent-security-moves-to-runtime-boundaries","slug":"agent-security-moves-to-runtime-boundaries","title":"Agent security moves to runtime boundaries","date":"2026-07-24","record_date":"2026-07-24","date_kind":"last_verified","source_count":7,"url":"https://newruntime.com/patterns/agent-security-moves-to-runtime-boundaries/"},{"kind":"Field Note","stable_id":"post:openai-hugging-face-security-incident","slug":"openai-hugging-face-security-incident","title":"OpenAI's Hugging Face Incident Makes Agent Sandboxes a Production Risk","date":"2026-07-22","record_date":"2026-07-22","date_kind":"updated_or_published_at","source_count":2,"url":"https://newruntime.com/posts/openai-hugging-face-security-incident/"},{"kind":"Field Note","stable_id":"post:pillar-sandbox-escapes","slug":"pillar-sandbox-escapes","title":"Coding Agent Sandboxes Break in Places Teams Do Not Expect","date":"2026-07-21","record_date":"2026-07-21","date_kind":"updated_or_published_at","source_count":1,"url":"https://newruntime.com/posts/pillar-sandbox-escapes/"},{"kind":"Raw Signal","stable_id":"signal:cubesandbox-microvm-execution-layer","slug":"cubesandbox-microvm-execution-layer","title":"CubeSandbox packages agent execution into isolated microVMs","date":"2026-07-14","record_date":"2026-07-14","date_kind":"observed_at","source_count":2,"url":"https://newruntime.com/signals/cubesandbox-microvm-execution-layer/"},{"kind":"Raw Signal","stable_id":"signal:trycase-disposable-linux-agent-verification","slug":"trycase-disposable-linux-agent-verification","title":"TryCase gives coding agents disposable Linux verification","date":"2026-07-10","record_date":"2026-07-10","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/trycase-disposable-linux-agent-verification/"},{"kind":"Raw Signal","stable_id":"signal:agentos-lightweight-runtime-for-coding-agents","slug":"agentos-lightweight-runtime-for-coding-agents","title":"agentOS packages a lightweight runtime for coding agents","date":"2026-06-29","record_date":"2026-06-29","date_kind":"observed_at","source_count":3,"url":"https://newruntime.com/signals/agentos-lightweight-runtime-for-coding-agents/"},{"kind":"Raw Signal","stable_id":"signal:claude-managed-agents-productize-the-production-runtime","slug":"claude-managed-agents-productize-the-production-runtime","title":"Claude Managed Agents Productize the Production Runtime","date":"2026-06-21","record_date":"2026-06-21","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/claude-managed-agents-productize-the-production-runtime/"},{"kind":"Raw Signal","stable_id":"signal:the-computer-becomes-a-runtime-assigned-to-the-agent","slug":"the-computer-becomes-a-runtime-assigned-to-the-agent","title":"The Computer Becomes a Runtime Assigned to the Agent","date":"2026-06-19","record_date":"2026-06-19","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/the-computer-becomes-a-runtime-assigned-to-the-agent/"},{"kind":"Raw Signal","stable_id":"signal:github-tencentcloud-cubesandbox-agent-security-runtime-boundaries","slug":"github-tencentcloud-cubesandbox-agent-security-runtime-boundaries","title":"GitHub / TencentCloud/CubeSandbox: Agent Security Runtime Boundaries","date":"2026-04-23","record_date":"2026-04-23","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/github-tencentcloud-cubesandbox-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:claude-agent-security-runtime-boundaries","slug":"claude-agent-security-runtime-boundaries","title":"Claude: Agent Security Runtime Boundaries","date":"2026-04-22","record_date":"2026-04-22","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/claude-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:sandboxed-code-migration-agents-openai-cookbook","slug":"sandboxed-code-migration-agents-openai-cookbook","title":"Sandboxed Code Migration Agents (OpenAI cookbook)","date":"2026-04-19","record_date":"2026-04-19","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/sandboxed-code-migration-agents-openai-cookbook/"},{"kind":"Raw Signal","stable_id":"signal:claude-mythos-project-glasswing","slug":"claude-mythos-project-glasswing","title":"Claude Mythos + Project Glasswing","date":"2026-04-10","record_date":"2026-04-10","date_kind":"observed_at","source_count":3,"url":"https://newruntime.com/signals/claude-mythos-project-glasswing/"}],"patterns":[{"kind":"Pattern","stable_id":"pattern:agent-security-moves-to-runtime-boundaries","slug":"agent-security-moves-to-runtime-boundaries","title":"Agent security moves to runtime boundaries","description":"The durable security boundary for an agent is the runtime that constrains what it can read, remember, execute, and authorize, not the prompt that asks it to behave.","date":"2026-07-24","record_date":"2026-07-24","date_kind":"last_verified","topics":["agent-security","runtime-controls","sandbox"],"source_count":7,"metric":"high","url":"https://newruntime.com/patterns/agent-security-moves-to-runtime-boundaries/"}],"field_notes":[{"kind":"Field Note","stable_id":"post:openai-hugging-face-security-incident","slug":"openai-hugging-face-security-incident","title":"OpenAI's Hugging Face Incident Makes Agent Sandboxes a Production Risk","description":"OpenAI's model-evaluation incident with Hugging Face shows that cyber-capable agents need containment, monitoring, and evaluation controls that survive long-horizon behavior.","date":"2026-07-22","record_date":"2026-07-22","date_kind":"updated_or_published_at","topics":["agent-security","cybersecurity","sandbox"],"source_count":2,"url":"https://newruntime.com/posts/openai-hugging-face-security-incident/"},{"kind":"Field Note","stable_id":"post:pillar-sandbox-escapes","slug":"pillar-sandbox-escapes","title":"Coding Agent Sandboxes Break in Places Teams Do Not Expect","description":"Pillar shows that agent sandboxes must be assessed not only around the agent process, but around files, configs, allowlisted commands, and local daemons the host later trusts.","date":"2026-07-21","record_date":"2026-07-21","date_kind":"updated_or_published_at","topics":["agent-security","coding-agents","sandbox"],"source_count":1,"url":"https://newruntime.com/posts/pillar-sandbox-escapes/"}],"raw_signals":[{"kind":"Raw Signal","stable_id":"signal:cubesandbox-microvm-execution-layer","slug":"cubesandbox-microvm-execution-layer","title":"CubeSandbox packages agent execution into isolated microVMs","description":"CubeSandbox provides open-source KVM microVM isolation, lifecycle controls, and per-agent Linux environments.","date":"2026-07-14","record_date":"2026-07-14","date_kind":"observed_at","topics":["agent-infrastructure","sandbox","security"],"source_count":2,"metric":"notable","url":"https://newruntime.com/signals/cubesandbox-microvm-execution-layer/"},{"kind":"Raw Signal","stable_id":"signal:trycase-disposable-linux-agent-verification","slug":"trycase-disposable-linux-agent-verification","title":"TryCase gives coding agents disposable Linux verification","description":"TryCase creates short-lived Linux environments where agents can run generated code and tests away from the developer's machine.","date":"2026-07-10","record_date":"2026-07-10","date_kind":"observed_at","topics":["coding-agents","sandbox","verification"],"source_count":1,"metric":"notable","url":"https://newruntime.com/signals/trycase-disposable-linux-agent-verification/"},{"kind":"Raw Signal","stable_id":"signal:agentos-lightweight-runtime-for-coding-agents","slug":"agentos-lightweight-runtime-for-coding-agents","title":"agentOS packages a lightweight runtime for coding agents","description":"Rivet's agentOS combines isolated execution, durable workflows, resource limits, and host-side secrets in a WebAssembly and Rust runtime.","date":"2026-06-29","record_date":"2026-06-29","date_kind":"observed_at","topics":["agent-runtime","coding-agents","sandbox"],"source_count":3,"metric":"notable","url":"https://newruntime.com/signals/agentos-lightweight-runtime-for-coding-agents/"},{"kind":"Raw Signal","stable_id":"signal:claude-managed-agents-productize-the-production-runtime","slug":"claude-managed-agents-productize-the-production-runtime","title":"Claude Managed Agents Productize the Production Runtime","description":"Managed infrastructure bundles execution, observability, persistence, and isolation around long-running agent workloads.","date":"2026-06-21","record_date":"2026-06-21","date_kind":"observed_at","topics":["managed-agents","observability","sandbox"],"source_count":1,"metric":"notable","url":"https://newruntime.com/signals/claude-managed-agents-productize-the-production-runtime/"},{"kind":"Raw Signal","stable_id":"signal:the-computer-becomes-a-runtime-assigned-to-the-agent","slug":"the-computer-becomes-a-runtime-assigned-to-the-agent","title":"The Computer Becomes a Runtime Assigned to the Agent","description":"Giving each agent an isolated machine turns browser, shell, files, and installed software into controlled execution infrastructure.","date":"2026-06-19","record_date":"2026-06-19","date_kind":"observed_at","topics":["agent-runtime","computer-use","sandbox"],"source_count":1,"metric":"notable","url":"https://newruntime.com/signals/the-computer-becomes-a-runtime-assigned-to-the-agent/"},{"kind":"Raw Signal","stable_id":"signal:github-tencentcloud-cubesandbox-agent-security-runtime-boundaries","slug":"github-tencentcloud-cubesandbox-agent-security-runtime-boundaries","title":"GitHub / TencentCloud/CubeSandbox: Agent Security Runtime Boundaries","description":"The archive captures GitHub / TencentCloud/CubeSandbox as a dated public record from GitHub / TencentCloud/CubeSandbox. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-23","record_date":"2026-04-23","date_kind":"observed_at","topics":["agent-harness","agent-security","agents","coding-agents","prompt-injection","sandbox","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/github-tencentcloud-cubesandbox-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:claude-agent-security-runtime-boundaries","slug":"claude-agent-security-runtime-boundaries","title":"Claude: Agent Security Runtime Boundaries","description":"The archive captures YouTube source as a dated public record from YouTube source. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-22","record_date":"2026-04-22","date_kind":"observed_at","topics":["agent-harness","agent-security","coding-agents","model-routing","prompt-injection","sandbox","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/claude-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:sandboxed-code-migration-agents-openai-cookbook","slug":"sandboxed-code-migration-agents-openai-cookbook","title":"Sandboxed Code Migration Agents (OpenAI cookbook)","description":"The archive captures Sandboxed Code Migration Agents (OpenAI cookbook) as a dated public record from OpenAI Developers / Sandboxed Code Migration Agent. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-19","record_date":"2026-04-19","date_kind":"observed_at","topics":["agent-security","agents","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/sandboxed-code-migration-agents-openai-cookbook/"},{"kind":"Raw Signal","stable_id":"signal:claude-mythos-project-glasswing","slug":"claude-mythos-project-glasswing","title":"Claude Mythos + Project Glasswing","description":"The archive captures Claude Mythos + Project Glasswing as a dated public record from Anthropic. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-10","record_date":"2026-04-10","date_kind":"observed_at","topics":["agent-security","agents","evals","observability","prompt-injection","sandbox","verification"],"source_count":3,"metric":"structural","url":"https://newruntime.com/signals/claude-mythos-project-glasswing/"},{"kind":"Raw Signal","stable_id":"signal:github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries","slug":"github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries","title":"GitHub / SafeAI-Lab-X/ClawKeeper: Agent Security Runtime Boundaries","description":"The archive captures GitHub / SafeAI-Lab-X/ClawKeeper as a dated public record from GitHub / SafeAI-Lab-X/ClawKeeper. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-07","record_date":"2026-04-07","date_kind":"observed_at","topics":["agent-harness","agent-security","agents","coding-agents","prompt-injection","sandbox","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:anthropic-claude-code-auto-mode-agent-security-runtime-boundaries","slug":"anthropic-claude-code-auto-mode-agent-security-runtime-boundaries","title":"Anthropic / Claude Code Auto Mode: Agent Security Runtime Boundaries","description":"The archive captures Anthropic / Claude Code Auto Mode as a dated public record from Anthropic / Claude Code Auto Mode. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-03-30","record_date":"2026-03-30","date_kind":"observed_at","topics":["agent-security","agents","claude","prompt-injection","sandbox","security"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/anthropic-claude-code-auto-mode-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries","slug":"openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries","title":"OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt: Agent Security Runtime Boundaries","description":"The archive captures OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt as a dated public record from OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-19","record_date":"2026-02-19","date_kind":"observed_at","topics":["agent-interfaces","agent-runtime","agent-security","agent-tools","agents","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries","slug":"aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries","title":"Aitmpl / Dangerous Command Blocker: Agent Security Runtime Boundaries","description":"The archive captures Aitmpl / Dangerous Command Blocker as a dated public record from Aitmpl / Dangerous Command Blocker. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-05","record_date":"2026-02-05","date_kind":"observed_at","topics":["agent-harness","agent-security","coding-agents","prompt-injection","sandbox","security","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries","slug":"blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries","title":"Blog / Moltworker Self Hosted Ai Agent: Agent Security Runtime Boundaries","description":"The archive captures Blog / Moltworker Self Hosted Ai Agent as a dated public record from Blog / Moltworker Self Hosted Ai Agent. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-04","record_date":"2026-02-04","date_kind":"observed_at","topics":["agent-security","agents","cloudflare","prompt-injection","sandbox","workers"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries","slug":"github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries","title":"GitHub / 0x4m4/hexstrike-ai: Agent Security Runtime Boundaries","description":"The archive captures GitHub / 0x4m4/hexstrike-ai as a dated public record from GitHub / 0x4m4/hexstrike-ai. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-04","record_date":"2026-02-04","date_kind":"observed_at","topics":["agent-protocols","agent-security","agents","interoperability","mcp","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:github-cloudflare-moltworker-agent-security-runtime-boundaries","slug":"github-cloudflare-moltworker-agent-security-runtime-boundaries","title":"GitHub / cloudflare/moltworker: Agent Security Runtime Boundaries","description":"The archive captures GitHub / cloudflare/moltworker as a dated public record from GitHub / cloudflare/moltworker. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-04","record_date":"2026-02-04","date_kind":"observed_at","topics":["agent-security","agents","inference","local-models","model-routing","prompt-injection","sandbox"],"source_count":3,"metric":"structural","url":"https://newruntime.com/signals/github-cloudflare-moltworker-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:google-developers-tailor-gemini-cli-to-your-workflow-with-agent-security-runtime-boundaries","slug":"google-developers-tailor-gemini-cli-to-your-workflow-with-agent-security-runtime-boundaries","title":"Google Developers / Tailor Gemini Cli To Your Workflow With: Agent Security Runtime Boundaries","description":"The archive captures Google Developers / Tailor Gemini Cli To Your Workflow With as a dated public record from Google Developers / Tailor Gemini Cli To Your Workflow With. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-03","record_date":"2026-02-03","date_kind":"observed_at","topics":["agent-protocols","agent-security","agents","interoperability","mcp","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/google-developers-tailor-gemini-cli-to-your-workflow-with-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:google-agent-security-runtime-boundaries","slug":"google-agent-security-runtime-boundaries","title":"Google: Agent Security Runtime Boundaries","description":"The archive captures X source as a dated public record from X source. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-31","record_date":"2026-01-31","date_kind":"observed_at","topics":["agent-security","agents","inference","local-models","model-routing","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/google-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:docs-agent-security-runtime-boundaries-1274","slug":"docs-agent-security-runtime-boundaries-1274","title":"Docs: Agent Security Runtime Boundaries","description":"The archive captures Docs as a dated public record from Docs. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-29","record_date":"2026-01-29","date_kind":"observed_at","topics":["agent-security","new-feature","prompt-injection","sandbox","tools"],"source_count":2,"metric":"structural","url":"https://newruntime.com/signals/docs-agent-security-runtime-boundaries-1274/"},{"kind":"Raw Signal","stable_id":"signal:docs-agent-security-runtime-boundaries","slug":"docs-agent-security-runtime-boundaries","title":"Docs: Agent Security Runtime Boundaries","description":"The archive captures Docs as a dated public record from Docs. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-28","record_date":"2026-01-28","date_kind":"observed_at","topics":["agent-security","agents","inference","local-models","model-routing","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/docs-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:blog-securing-agents-in-production-agentic-runtime-5191a0715240-agent-security-runtime-boundaries","slug":"blog-securing-agents-in-production-agentic-runtime-5191a0715240-agent-security-runtime-boundaries","title":"Blog / Securing Agents In Production Agentic Runtime 5191a0715240: Agent Security Runtime Boundaries","description":"The archive captures Blog / Securing Agents In Production Agentic Runtime 5191a0715240 as a dated public record from Blog / Securing Agents In Production Agentic Runtime 5191a0715240. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-25","record_date":"2026-01-25","date_kind":"observed_at","topics":["agent-runtime","agent-security","agent-tools","agents","prompt-injection","sandbox","security"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/blog-securing-agents-in-production-agentic-runtime-5191a0715240-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:blog-supply-chain-risk-of-agentic-ai-infecting-agent-security-runtime-boundaries","slug":"blog-supply-chain-risk-of-agentic-ai-infecting-agent-security-runtime-boundaries","title":"Blog / Supply Chain Risk Of Agentic Ai Infecting: Agent Security Runtime Boundaries","description":"The archive captures Blog / Supply Chain Risk Of Agentic Ai Infecting as a dated public record from Blog / Supply Chain Risk Of Agentic Ai Infecting. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-25","record_date":"2026-01-25","date_kind":"observed_at","topics":["agent-protocols","agent-security","interoperability","mcp","prompt-injection","sandbox","security"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/blog-supply-chain-risk-of-agentic-ai-infecting-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:manus-manus-sandbox-agent-security-runtime-boundaries","slug":"manus-manus-sandbox-agent-security-runtime-boundaries","title":"Manus / Manus Sandbox: Agent Security Runtime Boundaries","description":"The archive captures Manus / Manus Sandbox as a dated public record from Manus / Manus Sandbox. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-17","record_date":"2026-01-17","date_kind":"observed_at","topics":["agent-loops","agent-security","agents","automation","orchestration","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/manus-manus-sandbox-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:workos-enterprise-ai-agent-playbook-what-anthropic-openai-agent-security-runtime-boundaries","slug":"workos-enterprise-ai-agent-playbook-what-anthropic-openai-agent-security-runtime-boundaries","title":"Workos / Enterprise Ai Agent Playbook What Anthropic Openai: Agent Security Runtime Boundaries","description":"The archive captures Workos / Enterprise Ai Agent Playbook What Anthropic Openai as a dated public record from Workos / Enterprise Ai Agent Playbook What Anthropic Openai. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2025-11-25","record_date":"2025-11-25","date_kind":"observed_at","topics":["agent-protocols","agent-security","ai-adoption","future-of-work","org-design","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/workos-enterprise-ai-agent-playbook-what-anthropic-openai-agent-security-runtime-boundaries/"}],"atlas_records":[],"next_reads":[{"type":"related_material","path":"/patterns/agent-security-moves-to-runtime-boundaries/","reason":"Continue through the Sandbox topic.","url":"https://newruntime.com/patterns/agent-security-moves-to-runtime-boundaries/","title":"Agent security moves to runtime boundaries","media_type":"text/html"},{"type":"related_material","path":"/posts/openai-hugging-face-security-incident/","reason":"Continue through the Sandbox topic.","url":"https://newruntime.com/posts/openai-hugging-face-security-incident/","title":"OpenAI's Hugging Face Incident Makes Agent Sandboxes a Production Risk","media_type":"text/html"},{"type":"related_material","path":"/posts/pillar-sandbox-escapes/","reason":"Continue through the Sandbox topic.","url":"https://newruntime.com/posts/pillar-sandbox-escapes/","title":"Coding Agent Sandboxes Break in Places Teams Do Not Expect","media_type":"text/html"},{"type":"related_material","path":"/signals/cubesandbox-microvm-execution-layer/","reason":"Continue through the Sandbox topic.","url":"https://newruntime.com/signals/cubesandbox-microvm-execution-layer/","title":"CubeSandbox packages agent execution into isolated microVMs","media_type":"text/html"},{"type":"related_material","path":"/signals/trycase-disposable-linux-agent-verification/","reason":"Continue through the Sandbox topic.","url":"https://newruntime.com/signals/trycase-disposable-linux-agent-verification/","title":"TryCase gives coding agents disposable Linux verification","media_type":"text/html"}]}
