Sandboxing isn't enough: researcher asks who stops users from --dangerously-skip-permissions
moyix · x · 2026-10-06
Security researcher moyix pushes back on the cyber community's two common responses to recent agent security incidents—"just use sandboxes" and "alignment is a waste of time." Even with strong isolation, agents need access to real resources, and he asks what happens once models are in users' hands, who will immediately run them with --yolo / --dangerously-skip-permissions.
Related event: Security Researchers Debate Whether Sandboxes Suffice for Agent Safety(4 posts)→
More from coding & agent
- Deep agents ships multimodal upgrades: docx/pptx/xlsx support and file offloading — hwchase17 · 2026-10-06
- Twilio picks OpenAI DevDay's Dots: AI agents that keep working between chats — craigsdennis · 2026-10-06
- UCLA PhD's LLM agents produce 126K-line Lean 4 proof of MIP* = RE core theorem in 63 days — siyan_zhao · 2026-10-06
- Dev Experiments With an Artifacts Tab: Let Agents Package Work as Visual Overviews — charlieholtz · 2026-10-06
- User burns $107 in 90 minutes on Claude Code Cloud, billed like an API key — MicahBerkley · 2026-10-06
- Google Docs/Drive beats local markdown for keeping agent context in sync, dev finds — AI_Andrew · 2026-10-06