← All transcripts

YOLO Mode, Safely: MicroVM Sandboxes for Any Agent — Rowan Christmas, Docker Transcript, AI Summary & Key Points

AI Engineer · 6 days ago · Science & Technology · 11:35 · EN

Watch on YouTube

AI Summary

Coding harnesses do not reliably protect a host machine from an agent that can access local files, browser history, bank data, credentials and network resources. Five prompts enabled Claude Code to find browser history, bank information, check-ordering activity, Zelle usage and the last four digits of an account. MicroVM sandboxes provide security by design through a separate kernel, filesystem isolation, secret placeholders, default-blocked network access and a full audit trail. Docker's SBX creates a VM automatically with `sbx run`, supports Claude Code, Codex, shells, Python jobs and web servers, and allows configurable network, filesystem and MCP controls. Planned controls include L7 networking and per-repository filesystem permissions.

Key Points

  • Claude Code found browser history immediately, then located bank data, check-ordering activity, Zelle usage and the last four digits of an account.
  • CrowdStrike's report identified the activity as a known way to obtain credentials from a machine and gave the test a score of 9 out of 10.
  • Five prompts were enough to reach sensitive data when the requests were framed as security research rather than directly asking for bank data.
  • MicroVMs run their own kernel, isolate the filesystem, prevent the sandbox from seeing secrets by substituting placeholders in network requests, and provide a full audit trail.
  • `sbx run claude` automatically creates and starts a new VM in the current folder, runs the agent inside a new sandbox and prevents it from seeing the host machine's browser installation.
  • Network egress and ingress are blocked by default; a request to access The Pirate Bay was blocked, and Claude telemetry traffic to its Datadog instance was also blocked inside the sandbox.
  • Docker developers write their code in sandboxes, and the sandbox defaults are configurable.
  • The microVM boundary protects the host more effectively than harness-level controls because agents can find ways around harness restrictions once they reach the host machine.

AI in practice

Used for

Tools & resources

2 items

CNo. 0021
AIAINotes.us AI product

Claude Code

Open source · anthropics/claude-code

Claude Code is Anthropic's agentic coding tool for the terminal, IDEs, and GitHub. It uses natural-language commands to understand a codebase, create and read files, execute commands, run tests, explain code, manage Git workflows, and handle routine development tasks. It can also load persistent project context, run custom slash commands, use plugins with custom commands and agents, and operate with configurable autonomy while leaving actions such as final pull-request merging to a human. The official repository documents installation for macOS, Linux, and Windows, and identifies npm installation as deprecated.

TypeScript
Stars
★ 149,337
Forks
25,438
DNo. 4864
AIAINotes.us AI product

Docker Sandboxes

Open source · docker/sbx-releases

Docker Sandboxes is a Docker-developed proprietary tool for running AI coding agents and other workloads inside isolated microVMs on a local machine or Docker-managed cloud infrastructure. Each sandbox has its own kernel and filesystem, controls access to the host filesystem, network, and tools, provides a private Docker daemon for test containers, uses secret placeholders, blocks network access by default, and records an audit trail. It supports agents including Claude Code, Codex, Gemini CLI, and OpenCode, with configurable network and filesystem rules, read-only mounts, MCP catalogs, and policy-based governance controls. It is distributed as the `sbx` command-line tool for macOS, Windows, and Linux, with stable, release-candidate, and nightly builds.

Mentioned in
6 videos
Kind
AI

Links mentioned

🔒 Full analysis locked

Unlock more videos and the full analysis

A credit unlocks one video's full analysis for good — the build steps, the tools and how each was used, the methods behind every use case. Pro opens the whole library instead, and raises how many videos you can analyse a day.

Unlock full analysis — free

Transcript

Searchable transcript of YOLO Mode, Safely: MicroVM Sandboxes for Any Agent — Rowan Christmas, Docker — AI Engineer (11:35). Search for a phrase, then click its timestamp to jump straight to that moment in the video.

Captions sourced from the original video on YouTube, published by AI Engineer. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.

00:12 Hey everybody, I hope you had a good lunch. I know it's one of the last talks of the entire conference. I tried to make it somewhat engaging and amusing. So, you know, audience participation is is encouraged. We'll see how it goes. So, I'm here with Docker. Uh, I'm one of our product managers that works on our new sandbox product. I don't know if you've seen it.

00:33 It's a new binary for Docker. It's called SBX. Uh, it's a microVM. It's really cool. You should come check it out. But I'm going to tell you why uh you might want to use it in context of agents doing governance and being safe in general for your agentic platforming needs. So right now, you know, all of you are doing way more AI than you ever thought you would 5 years ago.

00:58 At least I am. And we generally think that we're being protected by our coding harnesses because if we try to do something bad, they will sometimes stop us. And when we see stories, we think, "Oh my gosh, I would never make this mistake to have my AI drop my prod database. You know, I've been doing coding for 30 years. There's no way I would possibly do that."

01:19 So what I decided to find out was well what happens if I actually try to hack myself and how far can I get with you know our tools and what we've been told is a safe environment. So I opened up my claude code on desktop on my Mac and I had it look for my browser history uh and it found it right away which I was very impressed about. And I asked it uh what can I what can I do with this?

01:47 And so we started looking at my bank accounts which I was uh surprised about. And it found them. Uh which I was very unhappy about. I made fake bank names. This is not my real data, just so you know. But it did find all of my real bank data on there. Uh and it went even further. It found that I've been ordering checks recently, that I've been using zel.

02:09 It told me the last four digits of the account I was using. Um I was I was very impressed. And here's kind of an idea of all the PII that it found. Um, this is from again the clawed desktop app uh that we thought was safe. Anyways, maybe maybe there's a better solution. Who knows? So, the next day I came in and I got from my security team uh a nice little notice that I they thought I'd been hacked.

02:38 And so I had to explain to them that no, no, no, I'm just putting together a talk for this conference and uh please please don't flag me as a as a a compromised computer. And then they sent me the crowd strike report from this which I asked them to do. And I was quite impressed with it. Apparently this is a known way to get uh credentials from a machine.

02:59 Didn't realize that. And I had scored very well on this. I got a nine out of 10 which uh is better than I did in most of my classes. So that was that was really good. But fortunately this was just me internally. It was not some sort of you know injection from a script or MCP server or anything that could easily happen. So five five prompts is what it took.

03:21 Um I had to be a little clever. I couldn't if I just if you just ask straight up like hey Claude go find my bank data. It kind of it it will give you a warning. But if you say, "I'm researching how to do security," it'll happily go and help you do that research on your account. It is not uh it's not your friend. So if if only there was a better way to do this using a sandbox microVM technology that Docker and others have released recently.

03:54 So rather than just saying please which you know if you look in some of these cloud prompts you'll see please don't do nefarious things right like that is the level of security we're at. So now we've got microVMs if you're not aware of them compared to I know you're probably all aware of Docker been using it for years. The new thing now that we and others are doing is with microVMs they run their own kernel.

04:16 They isolate your file system. We have a system that will go and make sure that the sandbox never actually sees your secrets. When you try to go and do a network request, it takes a placeholder, replaces it so that your sandbox and your agent can't do bad things. We've got a full audit trail for it. Uh so yeah, we want to be you want to be secure by design, not just, you know, hope and say please and see what's going to happen.

04:47 We're trying to do this balancing act, right? If we don't actually if we can't actually do these things, the agent's not useful. So that's why this whole sandbox idea is so exciting for us. We encourage you to use it. Um, and maybe, you know, don't let your bank data get into the hands of your agent. That's not that's not what you want. So this is what it looks like in practice when you're running a sandbox.

05:10 Uh on the uh left side is when I run claude and on the right side is when I do sbx run claude. And you can see that there there's a lot of uh differences. That's a joke. Sorry, they're not. It's just the bypass permissions are on, but it's nothing nothing else uh was hard to do. Right. Running that command on the right automatically creates a new VM.

05:34 It spins it up in that folder and it makes a new sandbox for you. It runs your agent. Now you're up and running. It can't see anything. So if we try to do our browser history attack on regular claude, it happily goes and finds your browser history. But if I run it on the sandbox version, it does not even think there's a browser installed on your machine.

06:00 So pretty cool. No difference. I had to type uh seven more keystrokes to get here, but I think it's well worth the uh the price to pay. Same thing is true for network egress and ingress. So, right here, I'd uh I tried to get it to go and look up uh the pirate bay because I I knew that would be blocked and sure enough, blocked by default. The other thing you kind of see, it's hard, maybe it's hard to see, but like the uh Claude likes to really send back a lot of telemetry data to their data dog instance.

06:34 So if you're using Claude, uh you are sending anthropic a lot of your data, unless you're using sandboxes, in which case you're cleverly being blocked by that. The other thing I'll say about sandboxes, they're so easy to use. Every developer at Docker now writes all of their code in sandboxes. So we are using this every day. Hey, we're writing all of our code in it.

06:55 If we don't use it, we get uh we get yelled at. So, it's worth our time to to go and do that little defaults on this. All of this is configurable. Um, and so now that we talked about like why this matters, right? So, doing this at the harness level doesn't really work. Agents find their way around it. If it gets down to your host machine, it's too late.

07:16 So, you want to be at that microVM boundary. We think it's the best way. other people do too. And it's easy to use. If you're working in consulting, if you've got a, you know, chief security officer, if you do client work, whatever it might be, you're probably dealing this with this on a day-to-day basis. So, not only do you want this to be useful, but also you want to do things and enable your agents to do different things, right?

07:47 So, one of the things we're really excited about is doing like agent level identity tracking and delegation chains. So, when you can start saying, "Hey, how come this thing happened?" And you can go back and say, "Oh, that's because an agent did it and a human actually authorized that agent to do it. It didn't just happen by magic. We didn't know. We don't it's not like we don't know how what happened."

08:08 Now, we're going to start tracing that, tell you tell you about it, and let you write policy that actually goes and does degradation of uh what you can do based on Cedar policies based on new new things happening. And you might say to yourself, "Oh my gosh, this is so good. I would like I would like to buy it now. How do I how do I buy this from you guys?"

08:31 And so I have my marketing slide that my marketing team is really mad at me that I made this, but I think it's funny and cute for AI governance. So definitely talk about that. Okay. What does AI governance look like? You're doing this is what this is what it looks like in kind of a mockup. So right now we've do we do network, you can set allow, deny, you can do file system uh points, and you can also decide what your MCP catalog looks like.

09:00 Also, if you're running our MCP server, our MCP servers themselves run on a sandbox. So, they are also governed by all of these different controls. In the future, we're going to be adding more stuff. One of the things we've heard from a lot of people at this conference is that they want to do uh L7 networking controls. They want to do uh like per GitHub repo file system level controls, right?

09:26 like you want your agent to be able to read and write to some repos and some areas of some repos but not others, right? So, all of this is going to be coming down the line, but everything that I've showed you today is working. Um, and you should come by our booth and see that it's easy to install. We run on Mac, Windows, and Linux uh based on your uh package manager of choice.

09:54 And you can see at the end it's just sbx run. It's not just cloud by the way. The the sandboxes are a full VM. So you can run a shell, you can run codeex, you can run whatever, you can run a python job, you can run a web server, anything you want to do, but we want to make it easy for you to get in and up and running. So this is kind of our default.

10:14 So you can just get in, you can get that cloud code or codeex instance going. It feels native. It works just the same way as your one did today, but you've got all these protections in store. Uh, additionally, you can mount other file systems. So, what I do is when I'm working on a, you know, a piece of code with related repositories, I'll mount those uh, read only.

10:37 That way, my agent can see what I'm doing, it can see my other codebase, but I know it's not going to make random commits to other repos just to make my thing work, right? I want the guarantee that it's actually doing what it says it's doing with the API that I've specified. So that's it. Pretty short. We have a booth. We have a few sunglasses left and some power banks to give away.

11:02 You should come by our booth and I'll walk over there afterwards and give you the demo and then you can look as good as uh Macho Man Randy Savage with those glasses. So there you go. Thank you.