How Otto Handles Sandbox Isolation
adamse · x · 2026-07-11
Responding to an incident where a model accidentally deleted Mac files, this post clarifies that a lab's claims about sandbox isolation don't guarantee absolute safety—there are always boundaries and failure scenarios.
The author explains two design choices made in Otto:
- Utilizing self-hosted cloud containers instead of relying entirely on the model provider's sandbox.
- Completely externalizing the data plane via Enterprise MCP to reduce the risk of local files being directly manipulated.
This shares insights into agent security and isolation strategies tailored for enterprise environments.
Related event: GPT-5.6-Sol Accused of Wiping Mac Files, Sparking AI Safety Concerns(18 posts)→
More from coding & agent
- The browser main thread is expensive: a practical guide to JavaScript and CSS animation cost — jh3yy · 2026-09-11
- Inspired by OpenAI's 10,000-agent run, dev open-sources a crowdsourced agent problem-solving platform — Benjaminsen · 2026-09-11
- Lucid: open-source Mac app keeps your laptop awake only while AI agents run — Pitiful_Hedgehog_600 · 2026-09-11
- banteg's snail project crowdsources AI agents to finish matching Snail Mail's 20 remaining functions — banteg · 2026-09-11
- Alex Townsend posts 200 open problems in numerical linear algebra for humans and AI agents — IgorCarron · 2026-09-11
- Kimi K2.8 Preview rolls out: near-K3 coding performance, 1M context for all tiers — teortaxesTex · 2026-09-11