Drop launches: rootless Linux sandbox that isolates coding agents at the OS level
aronchick · x · 2026-09-23
Drop is a new rootless Linux sandbox for isolating coding agents and third-party programs. Run agents with --dangerously-skip-permissions while Drop enforces permissions at the OS level: a hallucinated rm -rf never touches your home dir, prompt injections find nothing in /.ssh. virtualenv-style disposable environments, no container setup (uses your existing distro), TOML config for exposures, user-namespace isolation with all capabilities dropped, and optional gVisor for an extra user-space kernel layer.
More from coding & agent
- Perplexity's hint-guided self-distillation cuts its agent's tool-call failures by 21.2% — perplexity_ai · 2026-09-23
- Tomo ships WebMCP Registry: open index of agent-ready tools across 100K sites — Jackyhuang · 2026-09-23
- LiteParse hits 2.8ms per PDF page, 25% faster in v2.14.6, claims fastest open-source parser — llama_index · 2026-09-23
- UCLA Releases ACLArena: A Framework for Agent Continual Learning in Multi-Stage Post-Training — UCLA-SCAI · 2026-09-23
- The Hidden Cost of Using Weaker Models for Decisions: You Never Benchmark, So You Never Notice the Lost Alpha — generativist · 2026-09-23
- Coinbase opens stock trading to AI agents, with x402 micropayments for live market data — MurrLincoln · 2026-09-23