Open-Source Agent Chimera: Tool Whitelist + gVisor Sandbox
Federal-Teaching2800 · reddit · 2026-07-06
The creator of the open-source agent Chimera shared two security governance updates: First, a per-session tool whitelist (--allow-tools) ensures unauthorized tools never enter the model schema, preventing the agent from being tricked into calling them. Second, the sandbox switched to the gVisor runtime (runsc), using a user-space kernel to intercept container syscalls and reducing the host kernel's attack surface. The author also acknowledged limitations: the whitelist is opt-in by default, gVisor is still not a full VM, and this does not solve the core reliability challenges of agents.
More from coding & agent
- A 9B Ollama agent can run a fully local DJ radio with tools, memory, and TTS — pinku1 · 2026-07-27
- Bugbot rejects an MCP permission flag because it would break path-scoped isolation — zeeg · 2026-07-27
- One GPT-5.6 agent is guarding a Blink security system while another makes a parody rap album — repligate · 2026-07-27
- An agent got unblocked by reusing a logged-in browser, not stealth tricks — armanidev_ · 2026-07-27
- Paper argues graph topology can become the core operating system for AI agents — theomitsa · 2026-07-27
- Claude Code desktop adds UI markup feedback for smoother visual editing — EricBuess · 2026-07-27