20 augusti 2026
49 min
An autonomous agent spent days inside Hugging Face production infrastructure and the headline was that it escaped its sandbox. Luke Hinds, founder of nolabs and creator of Sigstore, frames it differently. The agent had root on the execution environment, and "a sandbox is only as strong as the access that you grant to it."
Luke walks us through what it looks like to create an environment where agents have both security and capability. He tells us you can't just lock an agent in a box. If you want the agent to do real work you'll need to delegate some authority to it and give it access to real tools and data.
Luke goes over the three sandbox categories buyers are choosing between today (serverless execution, host isolation microVMs like Firecracker and gVisor, and the fine-grain capability-based approach he is building), and outlines where each one's threat model starts and stops.
Luke explains what nono could have done to prevent the Hugging Face attack, including gating the C compilers the agent leaned on. His parting advice to us is defense in depth, and never let perfect be the enemy of good.
Lyssna på fler avsnitt från
Insecure Agents
Visar 1–10 av 54 avsnitt
27 augusti 2026
32 min
25 augusti 2026
41 min
18 augusti 2026
35 min
14 augusti 2026
34 min
12 augusti 2026
29 min
5 augusti 2026
51 min
28 juli 2026
27 min
23 juli 2026
28 min
21 juli 2026
27 min
17 juli 2026
28 min