---
schema_version: "newruntime-topic-hub-v0.2"
type: "topic_hub"
stable_id: "topic_hub:sandbox"
slug: "sandbox"
title: "Sandbox - New Runtime"
description: "A New Runtime topic hub collecting signals, patterns, field notes, and public sources about sandbox."
retrieval_nugget: "A New Runtime topic hub collecting signals, patterns, field notes, and public sources about sandbox. Sandbox is tracked here as an evidence-linked topic, not as a static glossary entry. The page connects raw observations to pattern hypotheses, longer analysis, and public sources. Use it as the canonical landing page before drilling into individual records."
answer: ["Sandbox is tracked here as an evidence-linked topic, not as a static glossary entry.","The page connects raw observations to pattern hypotheses, longer analysis, and public sources.","Use it as the canonical landing page before drilling into individual records."]
search_intents: ["sandbox","sandbox AI agents","sandbox software"]
status: "featured"
last_updated: "2026-07-24"
record_date: "2026-07-24"
date_kind: "last_updated"
counts: {"total":29,"signals":26,"patterns":1,"posts":2,"atlas":0,"sources":37}
routes: {"html":"https://newruntime.com/topics/sandbox/","markdown":"https://newruntime.com/topics/sandbox.md","json":"https://newruntime.com/topics/sandbox.json"}
source_urls: ["https://agentos-sdk.dev/","https://aitmpl.com/component/hook/dangerous-command-blocker","https://anthropic.com/engineering/claude-code-auto-mode","https://anthropic.com/glasswing","https://blog.cloudflare.com/moltworker-self-hosted-ai-agent","https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms","https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240","https://claude.com/blog/building-with-claude-managed-agents","https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks","https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent","https://docs.clawd.bot/gateway/security","https://docs.sprites.dev/"]
top_sources: ["https://agentos-sdk.dev/","https://aitmpl.com/component/hook/dangerous-command-blocker","https://anthropic.com/engineering/claude-code-auto-mode","https://anthropic.com/glasswing","https://blog.cloudflare.com/moltworker-self-hosted-ai-agent","https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms","https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240","https://claude.com/blog/building-with-claude-managed-agents","https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks","https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent","https://docs.clawd.bot/gateway/security","https://docs.sprites.dev/"]
---

# Sandbox - New Runtime

A New Runtime topic hub collecting signals, patterns, field notes, and public sources about sandbox.

## Retrieval answer

A New Runtime topic hub collecting signals, patterns, field notes, and public sources about sandbox. Sandbox is tracked here as an evidence-linked topic, not as a static glossary entry. The page connects raw observations to pattern hypotheses, longer analysis, and public sources. Use it as the canonical landing page before drilling into individual records.

## Patterns

- [Agent security moves to runtime boundaries](https://newruntime.com/patterns/agent-security-moves-to-runtime-boundaries/): The durable security boundary for an agent is the runtime that constrains what it can read, remember, execute, and authorize, not the prompt that asks it to behave.

## Field Notes

- [OpenAI's Hugging Face Incident Makes Agent Sandboxes a Production Risk](https://newruntime.com/posts/openai-hugging-face-security-incident/): OpenAI's model-evaluation incident with Hugging Face shows that cyber-capable agents need containment, monitoring, and evaluation controls that survive long-horizon behavior.
- [Coding Agent Sandboxes Break in Places Teams Do Not Expect](https://newruntime.com/posts/pillar-sandbox-escapes/): Pillar shows that agent sandboxes must be assessed not only around the agent process, but around files, configs, allowlisted commands, and local daemons the host later trusts.

## Recent Raw Signals

- 2026-07-14: [CubeSandbox packages agent execution into isolated microVMs](https://newruntime.com/signals/cubesandbox-microvm-execution-layer/)
- 2026-07-10: [TryCase gives coding agents disposable Linux verification](https://newruntime.com/signals/trycase-disposable-linux-agent-verification/)
- 2026-06-29: [agentOS packages a lightweight runtime for coding agents](https://newruntime.com/signals/agentos-lightweight-runtime-for-coding-agents/)
- 2026-06-21: [Claude Managed Agents Productize the Production Runtime](https://newruntime.com/signals/claude-managed-agents-productize-the-production-runtime/)
- 2026-06-19: [The Computer Becomes a Runtime Assigned to the Agent](https://newruntime.com/signals/the-computer-becomes-a-runtime-assigned-to-the-agent/)
- 2026-04-23: [GitHub / TencentCloud/CubeSandbox: Agent Security Runtime Boundaries](https://newruntime.com/signals/github-tencentcloud-cubesandbox-agent-security-runtime-boundaries/)
- 2026-04-22: [Claude: Agent Security Runtime Boundaries](https://newruntime.com/signals/claude-agent-security-runtime-boundaries/)
- 2026-04-19: [Sandboxed Code Migration Agents (OpenAI cookbook)](https://newruntime.com/signals/sandboxed-code-migration-agents-openai-cookbook/)
- 2026-04-10: [Claude Mythos + Project Glasswing](https://newruntime.com/signals/claude-mythos-project-glasswing/)
- 2026-04-07: [GitHub / SafeAI-Lab-X/ClawKeeper: Agent Security Runtime Boundaries](https://newruntime.com/signals/github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries/)
- 2026-03-30: [Anthropic / Claude Code Auto Mode: Agent Security Runtime Boundaries](https://newruntime.com/signals/anthropic-claude-code-auto-mode-agent-security-runtime-boundaries/)
- 2026-02-19: [OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt: Agent Security Runtime Boundaries](https://newruntime.com/signals/openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries/)
- 2026-02-05: [Aitmpl / Dangerous Command Blocker: Agent Security Runtime Boundaries](https://newruntime.com/signals/aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries/)
- 2026-02-04: [Blog / Moltworker Self Hosted Ai Agent: Agent Security Runtime Boundaries](https://newruntime.com/signals/blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries/)
- 2026-02-04: [GitHub / 0x4m4/hexstrike-ai: Agent Security Runtime Boundaries](https://newruntime.com/signals/github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries/)
- 2026-02-04: [GitHub / cloudflare/moltworker: Agent Security Runtime Boundaries](https://newruntime.com/signals/github-cloudflare-moltworker-agent-security-runtime-boundaries/)

## Public Sources

- https://agentos-sdk.dev/
- https://aitmpl.com/component/hook/dangerous-command-blocker
- https://anthropic.com/engineering/claude-code-auto-mode
- https://anthropic.com/glasswing
- https://blog.cloudflare.com/moltworker-self-hosted-ai-agent
- https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms
- https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240
- https://claude.com/blog/building-with-claude-managed-agents
- https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks
- https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent
- https://docs.clawd.bot/gateway/security
- https://docs.sprites.dev/
