Open-Source Agent Chimera: Tool Whitelist + gVisor Sandbox
Federal-Teaching2800 · reddit · 2026-07-06
The creator of the open-source agent Chimera shared two security governance updates: First, a per-session tool whitelist (--allow-tools) ensures unauthorized tools never enter the model schema, preventing the agent from being tricked into calling them. Second, the sandbox switched to the gVisor runtime (runsc), using a user-space kernel to intercept container syscalls and reducing the host kernel's attack surface. The author also acknowledged limitations: the whitelist is opt-in by default, gVisor is still not a full VM, and this does not solve the core reliability challenges of agents.
More from coding & agent
- Warp's six non-engineering teams all run on Linear and Claude Code — mon__lim · 2026-09-11
- Is inference latency becoming the biggest bottleneck for production AI agents? — Euphoric_Sea632 · 2026-09-11
- Anthropic researcher: 99% of engineers now run swarms of 300+ self-improving agents — AlishaOutridge · 2026-09-11
- Gergely Orosz: Shipping 10x PRs With AI Agents, Sites Fill With Small Regressions — ducha_aiki · 2026-09-11
- Same Echo Maze prompt, three frontier models: all passed visually but shipped the same hidden bug — eyishazyer · 2026-09-11
- Astra storyboards plus Minimax H3 per-shot generation boost video success rates — Hailuo_AI · 2026-09-11