







Fences, not Sandboxes
fencesandbox/fence
Lightweight, container-free sandbox for running commands with network and filesystem restrictions
A thousand ways to sandbox an agent
There are a thousand ways to sandbox an agent. Okay, I lied. There are three: simulated, containers, and microVMs. Here's when to use each.

What Anthropic’s Mythos and Project Glasswing Mean for Your Apple Devices - TidBITS
AI is accelerating the discovery of security vulnerabilities, transforming the landscape of digital security. But Apple users are in a good spot, thanks to Apple’s focus on security and control over the entire ecosystem. TidBITS Security Editor Rich Mogull explains Anthropic’s Mythos and Project Glasswing.
Moats & Drawbridges - augment
In a world obsessed with moats, the open social web drops drawbridges
Docker Sandboxes: Run Agents in YOLO Mode, Safely | Docker
Learn from Docker experts to simplify and advance your app development and management with Docker. Stay up to date on Docker events and new version

anthropic-experimental/sandbox-runtime
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.
Jekyll-Bonsai
A modern jekyll theme for semantically inclined digital gardeners.
Quantifying Frontier LLM Capabilities for Container Sandbox Escape
AI agents are demonstrating rapid improvement in capabilities: the length of some tasks that frontier models can complete autonomously—measured in human-equivalent time—has been doubling approximately every seven months (METR, 2025; AI Security Institute, 2025a). In cybersecurity, current models achieve non-trivial success (Zhang et al., 2025) on professional-level Capture the Flag challenges, and recent evaluations report 13% success rates on exploiting real-world web application vulnerabilities (Zhu et al., 2025b). These results indicate that modern models can already perform multi-step vulnerability discovery and exploitation.
On Thickets, Enclosure, and Leaving
Every platform I left, I left for the same pattern: enclosure by othering — systems that define what is shameful, create targets, and point an aggressive majority at them. Substack's AI-detection turn is the latest, and it is Dark Forestry in action. The escape is spatial: go where the platforms ar…

Sprites - Stateful sandboxes
Persistent, hardware-isolated execution environments for arbitrary code. Run AI agents, untrusted code, and more in secure sandbox environments with checkpoint & restore.
It's that time of the week again! Today, we're sharing Chalk, a document editor that shows how apps that need fine-grained permissioning can be built on spaces. Chalk is built on our last three releases!
Habitat's road to release: 04 Chalk
habitat.leaflet.pubMaybe the real moats are the drawbridges we'll build along the way? In my latest augment piece, I re-think "moats" for the open social web by seeing what @standard.site, @blackskyweb.xyz's Acorn, and bridges like @ap.brid.gy + @wafrn.net have done for the ecosystem.
Moats & Drawbridges
www.augment.ink