Docker engineer: agents should hold zero credentials in sandboxes, with MCP gateways as the control point
AI Engineer · youtube · 2026-10-06
At AI Engineer World's Fair, Docker principal software engineer Jim Clark argued agent safety comes from limiting tools and context, not from harnesses: as agents run longer unsupervised, the boundary to manage is the sandbox.
- Core claim: The right number of credentials in a sandbox is zero; model each sandbox on the task's intent so untrusted input never mixes with dangerous tools.
- Examples: A newsroom split into researcher / fact-checker / publisher sandboxes; a coding agent that gets signing keys only when committing.
- MCP gateway: One gateway endpoint per sandbox serves as the single control point for tools, resources and prompts, making harnesses swappable.
- Identity: Cross App Access (XAA) with Okta lets agents reuse existing SSO, plus progressive disclosure of tools.
- Try it: brew install sbx, with open-source docker/mcp-gateway and Docker Sandboxes docs.
More from coding & agent
- Prompt craft: using Opus 5.5 with JS Canvas to draw a Chinese seal-script seal — dotey · 2026-10-06
- "It's insane that coding is now just audibly speaking at your computer" — KevinNaughtonJr · 2026-10-06
- Reason Machines launches Reason 1.0, a frontier coding agent with free daily usage — kalyan_kpl · 2026-10-06
- SkillFoundry at COLM 2026: self-evolving agent skill libraries from scientific resources — jmuiuc · 2026-10-06
- A minimal protein structure predictor in ~200 lines of readable PyTorch — CatAstro_Piyush · 2026-10-06
- Tootsy: open-source browser sidebar AI agent with local models, guardrails, and page automation — KrakenSG · 2026-10-06