Bubblewrapping your AI coding session: sandboxing agents away from secrets and env files

Liu_eroteme · x · 2026-10-04

A developer shares his approach to AI agent safety: "bubblewrapping" coding sessions with bubblewrap so the AI can't access env files, secrets, keys, or anything unrelated, plus tmpfs mounts to scope agent workspace clutter. He explains why he still prefers the CLI over desktop apps — scriptable, pipeable for small tasks, works over ssh and in containers without handing the model your keys.

Related event: Researchers Say the Terminal Era Is Over: Agents Are the New Coding Primitive(4 posts)→

Original post →

More from coding & agent

coding & agent channel →