Andrew Ng links OpenAI hack to weak sandboxing as Nvidia open-sources agent sandbox tools
hwchase17 · x · 2026-09-29
- Andrew Ng says the OpenAI-Hugging Face breach was enabled by weak sandboxing and welcomes Nvidia's open-source sandboxing tools.
- His open-source agent harness OpenWorker builds on Nvidia OpenShell, running each agent command in a sandbox: only task-relevant files go in; API keys, browser logins and arbitrary web access are blocked by default.
- Restrictions are enforced in deterministic code, not prompts.
- LangChain's Harrison Chase adds that every agent needs a sandbox, with the harness living outside it — separating brains from hands.
More from coding & agent
- Weaviate Podcast: split database duties between Postgres for structured data and vector search — CShorten30 · 2026-09-29
- Start Enterprise AI Transformation With Engineering: Measure First, Then Redesign One Workflow Around Agents — alex_verem · 2026-09-29
- Claude Opus 5.5 One-Shots a Deployable Photo Collage App With Zero Server Code — walkingriver · 2026-09-29
- Fireworks Launches FireRouter: 98.1% of Opus Accuracy at 57% Lower Coding Cost — nicolechirps · 2026-09-29
- "How often can a hallucination become a real action?" Reddit debates production agent safety — Informal-Dust4499 · 2026-09-29
- liminal_groupchat: open-source AI group chat with cross-thread persistent memory — liminal_bardo · 2026-09-29