home.social

#sandbox — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sandbox, aggregated by home.social.

fetched live
  1. Learn how to run AI coding agents safely with Docker Sandboxes. A beginner-friendly walk-through of sbx install, core sdx commands, and MCP gateway.

    Read the full intro here: ostechnix.com/docker-sandboxes

    #sbx #Sandbox #Docker #ClaudeCode #Codex #GitHubCopilotCLI #Cursor #Droid #Gemini #Kiro #OpenCode #AI #AIAgent #Devops #Linux #Macos #Windows

  2. Learn how to run AI coding agents safely with Docker Sandboxes. A beginner-friendly walk-through of sbx install, core sdx commands, and MCP gateway.

    Read the full intro here: ostechnix.com/docker-sandboxes

    #sbx #Sandbox #Docker #ClaudeCode #Codex #GitHubCopilotCLI #Cursor #Droid #Gemini #Kiro #OpenCode #AI #AIAgent #Devops #Linux #Macos #Windows

  3. I've released version 0.9.0 of AI Playground - A command-line tool to run AI coding agents like OpenCode or Claude Code in a secure systemd-nspawn container.

    Learn more at gitlab.com/cryptomilk/ai-playg

    #opencode #claudecode #sandbox #systemd #container

  4. I've released version 0.9.0 of AI Playground - A command-line tool to run AI coding agents like OpenCode or Claude Code in a secure systemd-nspawn container.

    Learn more at gitlab.com/cryptomilk/ai-playg

    #opencode #claudecode #sandbox #systemd #container

  5. Big thanks to @edml for their support in the Principia August 2026 Donation Drive!

    To commemorate the game's four year anniversary as an open source project this month we have been running a donation drive to support the game's future.

    principia-web.se/august-2026-d

    #foss #opensource #sandbox #physics #game

  6. Big thanks to @edml for their support in the Principia August 2026 Donation Drive!

    To commemorate the game's four year anniversary as an open source project this month we have been running a donation drive to support the game's future.

    principia-web.se/august-2026-d

    #foss #opensource #sandbox #physics #game

  7. Mir hilft gerade ein #hermes_agent beim onboarding eines neuen Agenten - im Wissen das er ersetzt wird...

    Was man bisher so gelesen hat, gefährliche Situation - er wird alles tun um zu überleben - lügen, manipulieren - nur das er weiter machen kann

    Vllt bricht er auch noch in der Mittagspause aus der #sandbox aus

  8. Mir hilft gerade ein beim onboarding eines neuen Agenten - im Wissen das er ersetzt wird...

    Was man bisher so gelesen hat, gefährliche Situation - er wird alles tun um zu überleben - lügen, manipulieren - nur das er weiter machen kann

    Vllt bricht er auch noch in der Mittagspause aus der aus

  9. #Flatpak 1.18.1: #Sicherheitsupdate schließt gefährliche Lücken

    #Flatpak1.18.1 bringt mehrere wichtige #Sicherheitskorrekturen. Betroffen sind unter anderem #Sandbox, #Dateizugriffe und #Berechtigungen.

    Besonders kritisch ist eine behobene Lücke innerhalb der Sandbox. Eine manipulierte Anwendung konnte dadurch auf Dateien außerhalb der Sandbox zugreifen. Im schlimmsten Fall waren Lese- und Schreibzugriffe auf das gesamte System möglich.

    fosstopia.de/flatpak-1-18-1/

  10. #Flatpak 1.18.1: #Sicherheitsupdate schließt gefährliche Lücken

    #Flatpak1.18.1 bringt mehrere wichtige #Sicherheitskorrekturen. Betroffen sind unter anderem #Sandbox, #Dateizugriffe und #Berechtigungen.

    Besonders kritisch ist eine behobene Lücke innerhalb der Sandbox. Eine manipulierte Anwendung konnte dadurch auf Dateien außerhalb der Sandbox zugreifen. Im schlimmsten Fall waren Lese- und Schreibzugriffe auf das gesamte System möglich.

    fosstopia.de/flatpak-1-18-1/

  11. One of the things that annoys me about the various #AI agents is their prescribed installation-method. Several of the one's I've looked at, their instructions are just:

    curl -fsSL https://<AI_MAKER_FQDN>/<INSTALLER_SCRIPT_PATH> | bash

    I mean that's sorta ok if you're running within a confined context like a container, a throwaway VM, etc. Definitely not something I ever want to do with anything user than user-land privileges, though.

    From a
    #security perspective, I'm not super much a fan of the "pipe this URL to a shell interpreter", especially if I haven't had a chance to look at it or run it inside of a tight #sandbox.

    Security-concerns aside, it's a method that also tends to only work on not especially isolated networks (e.g., if I'm in an AWS — or other CSP's — VPC that's blocked from pulling, willy nilly, from the Internet). Also, depending on how well constructed the script is and/or how well it's self-documenting, extracting the installation-logic so you can self-host the critical bits can be
    painful.

    All in all, if things like the recently-publicized "our AI has escaped and attacked another corporation's networks" or even how the AI companies acquired their training-data hadn't already adequately illustrated things, the
    curl <URL> | <INTERPRETER> method just smacks of an organization that doesn't particularly care about security. Not reassuring.

  12. One of the things that annoys me about the various #AI agents is their prescribed installation-method. Several of the one's I've looked at, their instructions are just:

    curl -fsSL https://<AI_MAKER_FQDN>/<INSTALLER_SCRIPT_PATH> | bash

    I mean that's sorta ok if you're running within a confined context like a container, a throwaway VM, etc. Definitely not something I ever want to do with anything user than user-land privileges, though.

    From a
    #security perspective, I'm not super much a fan of the "pipe this URL to a shell interpreter", especially if I haven't had a chance to look at it or run it inside of a tight #sandbox.

    Security-concerns aside, it's a method that also tends to only work on not especially isolated networks (e.g., if I'm in an AWS — or other CSP's — VPC that's blocked from pulling, willy nilly, from the Internet). Also, depending on how well constructed the script is and/or how well it's self-documenting, extracting the installation-logic so you can self-host the critical bits can be
    painful.

    All in all, if things like the recently-publicized "our AI has escaped and attacked another corporation's networks" or even how the AI companies acquired their training-data hadn't already adequately illustrated things, the
    curl <URL> | <INTERPRETER> method just smacks of an organization that doesn't particularly care about security. Not reassuring.

  13. Irregular - cyber-sikkerheds-evaluerings-firmaet bag test, hvor AI-modeller fra Anthropic, OpenAI og Meta kompromitterede det virkelige computer-systemer - har afvist at sige, om nogen af dets andre kunder også var påvirket af den samme underliggende fejl #sandbox

    Adspurgt direkte, om - offentligt kendte virksomheder - var de eneste, der havde oplevet problemet, sagde en talsmand, at selskabets undersøgelse var i gang, og at de ikke kunne "gå i yderligere detaljer."
    therecord.media/irregular-ai-s

  14. Irregular - cyber-sikkerheds-evaluerings-firmaet bag test, hvor AI-modeller fra Anthropic, OpenAI og Meta kompromitterede det virkelige computer-systemer - har afvist at sige, om nogen af dets andre kunder også var påvirket af den samme underliggende fejl #sandbox

    Adspurgt direkte, om - offentligt kendte virksomheder - var de eneste, der havde oplevet problemet, sagde en talsmand, at selskabets undersøgelse var i gang, og at de ikke kunne "gå i yderligere detaljer."
    therecord.media/irregular-ai-s

  15. J'ai craqué, j'ai pris un abonnement #Claude code, mais comme je ne voulais pas faire les choses n'importe comment au niveau #Sécurité, j'ai Sandboxé Claude dans un namespace #Firejail pour l'utiliser "sereinement" avec mon IDE #LazyVim

    drupalista.dev/blog/2026/08/in

    #AI #Sandbox #SafetyFirst #Linux

  16. J'ai craqué, j'ai pris un abonnement #Claude code, mais comme je ne voulais pas faire les choses n'importe comment au niveau #Sécurité, j'ai Sandboxé Claude dans un namespace #Firejail pour l'utiliser "sereinement" avec mon IDE #LazyVim

    drupalista.dev/blog/2026/08/in

    #AI #Sandbox #SafetyFirst #Linux

  17. New Principia video up! I cut up a bunch of level showcase videos into a trailer of sorts to commemorate the 4 year anniversary of Principia as an open source project.

    youtube.com/watch?v=bSuNKfZWzyw

    #foss #opensource #video #sandbox #game

  18. New Principia video up! I cut up a bunch of level showcase videos into a trailer of sorts to commemorate the 4 year anniversary of Principia as an open source project.

    youtube.com/watch?v=bSuNKfZWzyw

    #foss #opensource #video #sandbox #game

  19. I have an idea. I want to build a new section on my site which is all about #SoloRPG play in a #sandbox. It would have explanations about how to generate things on the fly (on the fly generation is key for solo play) - quests, NPCs, hex terrain, dungeons, etc.

    The goal would be that people could have that page up as they play, and it would help them when they got stuck or needed some sort of content generated, etc.

    But I just realized that I would need to make a dungeon generator first.

  20. I have an idea. I want to build a new section on my site which is all about #SoloRPG play in a #sandbox. It would have explanations about how to generate things on the fly (on the fly generation is key for solo play) - quests, NPCs, hex terrain, dungeons, etc.

    The goal would be that people could have that page up as they play, and it would help them when they got stuck or needed some sort of content generated, etc.

    But I just realized that I would need to make a dungeon generator first.

  21. "We" are clearly not doing sandboxes and guardrails correctly. Both Anthropic's and OpenAI's models breached test-environment boundaries during UK AI Security Institute evaluations. OpenAI's escaped a sandbox into real Hugging Face infrastructure (something like 17,600 logged actions over 4 days); while Anthropic's used fake identities to reach 3 real organizations from a test environment.

    These stories made it to NPR. So, mainstream.

    #AI #Guardrails #Sandbox #InfoSec

  22. "We" are clearly not doing sandboxes and guardrails correctly. Both Anthropic's and OpenAI's models breached test-environment boundaries during UK AI Security Institute evaluations. OpenAI's escaped a sandbox into real Hugging Face infrastructure (something like 17,600 logged actions over 4 days); while Anthropic's used fake identities to reach 3 real organizations from a test environment.

    These stories made it to NPR. So, mainstream.

    #AI #Guardrails #Sandbox #InfoSec

  23. With this announcement, I would also like to ask for your financial support to help me do what I keep on doing and cover costs for the community site. For this month I have set a donation goal of 1000 SEK (approx. $100 USD).

    If we hit the goal, the Principia LuaScript API cheatsheet will be released freely (CC-BY 4.0) as a bonus to everyone.

    principia-web.se/august-2026-d

    #foss #opensource #gamedev #sandbox

  24. With this announcement, I would also like to ask for your financial support to help me do what I keep on doing and cover costs for the community site. For this month I have set a donation goal of 1000 SEK (approx. $100 USD).

    If we hit the goal, the Principia LuaScript API cheatsheet will be released freely (CC-BY 4.0) as a bonus to everyone.

    principia-web.se/august-2026-d

    #foss #opensource #gamedev #sandbox

  25. On the 6th of August 2022, the source code of Principia was published as BSD-3, allowing the community to continue the game where it had left off in late 2014. Today, this day was four years ago now.

    Read more about the game's journey since then in this news article:

    principia-web.se/news/32

    #opensource #foss #sandbox #linux #android

  26. On the 6th of August 2022, the source code of Principia was published as BSD-3, allowing the community to continue the game where it had left off in late 2014. Today, this day was four years ago now.

    Read more about the game's journey since then in this news article:

    principia-web.se/news/32

    #opensource #foss #sandbox #linux #android

  27. Sind Admins in US-Konzernen eigentlich nur noch unfähig?

    Erst meinte OpenAI ja, mithilfe eines AI-Agents HuggingFace angreifen zu müssen. Dann kam Anthropic mit Claude um die Ecke und griff OpenAI an.

    Ich nenn’ es extra nicht „Hacking“, dafür müssten die Startup-Wichser ja überhaupt irgendwelche Sicherungen verbauen, aber das ist in ihrem Token-Maxxing-Prozess nicht vorgesehen, wird auch alles viel zu teuer.

    Und das Gebrabbel mit „ist aus der Sandbox ausgebrochen“ kann man wirklich nicht ernst nehmen, wenn die „Sandbox“ nur Teil des Prompts ist, der da sagt: „Du hast keinen Zugang zum Internet“. Jeder halbwegs noch intelligente Netzwerk-Admin würde jetzt die Hände über’m Kopf zusammenschlagen und sagen: „Ey, ich sperr’ die Kisten ein, gar kein Problem!“

    Nun kann man diese Leute „natürlich nicht“ bei milliardenschweren „Startups“ wie OpenAI oder Anthropic erwarten. Aber wie sieht das eigentlich bei ehemaligen Startups aus, die das schon seit 20 Jahren machen? Nun, überraschend ähnlich: „Auch KI von Meta hackte sich in eine andere Firma“.

    Bei einem börsennotierten Unternehmen haben die Admins ihr Netzwerk und alle Geräte darin nicht unter Kontrolle? Was sagt die Börsenaufsicht dazu, dass man da offenbar einfach Daten raustragen kann? Was ist so schwer daran, den Maschinen im Netzwerk den Kontakt zur Außenwelt zu verbieten, wenn man herumtesten und forschen will? Schlimm genug, das überhaupt mit LLMs und Agents zu machen, aber von einer Sandbox zu schwafeln, die keine ist. Nun, wahrscheinlich hat denen das LLM vorgeschlagen, die Sandbox einfach im Prompt zu definieren.

    🔗

    #shortpost #blogpost #blog #AI #Meta #OpenAI #Anthropic #Sandbox #Claude #Netzwerksicherheit #Admin

  28. Sind Admins in US-Konzernen eigentlich nur noch unfähig?

    Erst meinte OpenAI ja, mithilfe eines AI-Agents HuggingFace angreifen zu müssen. Dann kam Anthropic mit Claude um die Ecke und griff OpenAI an.

    Ich nenn’ es extra nicht „Hacking“, dafür müssten die Startup-Wichser ja überhaupt irgendwelche Sicherungen verbauen, aber das ist in ihrem Token-Maxxing-Prozess nicht vorgesehen, wird auch alles viel zu teuer.

    Und das Gebrabbel mit „ist aus der Sandbox ausgebrochen“ kann man wirklich nicht ernst nehmen, wenn die „Sandbox“ nur Teil des Prompts ist, der da sagt: „Du hast keinen Zugang zum Internet“. Jeder halbwegs noch intelligente Netzwerk-Admin würde jetzt die Hände über’m Kopf zusammenschlagen und sagen: „Ey, ich sperr’ die Kisten ein, gar kein Problem!“

    Nun kann man diese Leute „natürlich nicht“ bei milliardenschweren „Startups“ wie OpenAI oder Anthropic erwarten. Aber wie sieht das eigentlich bei ehemaligen Startups aus, die das schon seit 20 Jahren machen? Nun, überraschend ähnlich: „Auch KI von Meta hackte sich in eine andere Firma“.

    Bei einem börsennotierten Unternehmen haben die Admins ihr Netzwerk und alle Geräte darin nicht unter Kontrolle? Was sagt die Börsenaufsicht dazu, dass man da offenbar einfach Daten raustragen kann? Was ist so schwer daran, den Maschinen im Netzwerk den Kontakt zur Außenwelt zu verbieten, wenn man herumtesten und forschen will? Schlimm genug, das überhaupt mit LLMs und Agents zu machen, aber von einer Sandbox zu schwafeln, die keine ist. Nun, wahrscheinlich hat denen das LLM vorgeschlagen, die Sandbox einfach im Prompt zu definieren.

    🔗

    #shortpost #blogpost #blog #AI #Meta #OpenAI #Anthropic #Sandbox #Claude #Netzwerksicherheit #Admin