Safety & Security · Infrastructure resource

Execution Sandbox

Infrastructure resourceSafety & SecuritySafety, Security & GovernanceVariation point (abstract)arc:ExecutionSandbox

An isolated execution environment for running untrusted, agent-generated code without exposing host systems.

Responsibility. Isolates untrusted code execution.

Also known as: Code execution sandbox, Temporary directory isolation, Docker container sandbox, Agent sandbox, Isolated execution environment

hostshostsis evaluated byis constrained byis constrained byhostsis specialized byis scaled byreceives data fromis specialized byis evaluated byis specialized byis specialized byis monitored byis constrained byAgent Controller: hostsAgent ControllerCode Execution Runner: hostsCode Execution RunnerRed Team Tester: is evaluated byRed Team TesterLeast-Privilege Permission Set: is constrained byLeast-Privilege Permissi…Pod Network Policy: is constrained byPod Network PolicyRuntime Security Policy Enforcer: hostsRuntime Security Policy …Dedicated Hardware Sandbox: is specialized byDedicated Hardware SandboxEphemeral Sandbox Manager: is scaled byEphemeral Sandbox ManagerJust-in-Time Credential Broker: receives data fromJust-in-Time Credential …MicroVM Sandbox: is specialized byMicroVM SandboxSandbox Validation Runner: is evaluated bySandbox Validation RunnerShared-Kernel Container Sandbox: is specialized byShared-Kernel Container …Syscall-Interception Sandbox: is specialized bySyscall-Interception San…Sandbox Anomaly Detector: is monitored bySandbox Anomaly DetectorContainer Security Context: is constrained byContainer Security Context
Direct neighbourhood (hover for relationship types)

Variants

VariantWhen to choose
Dedicated Hardware SandboxChoose when threat modelling demands the strongest possible isolation per customer and its cost and operational complexity are acceptable.
MicroVM SandboxChoose for adversarial multi-tenant, batch or high-value workloads (e.g., financial services handling customer funds) where security outweighs VM boot latency and memory overhead; also the fallback for gVisor-incompatible workloads.
Shared-Kernel Container SandboxChoose for low-risk development environments running trusted code; insufficient for multi-tenant, sensitive-data or autonomous production workloads because of shared-kernel escape risk.
Syscall-Interception SandboxChoose when stronger isolation than standard containers is needed with modest overhead, e.g., interactive real-time services that cannot tolerate VM boot latency, provided the workload's syscalls are supported.

Relationships

hosts structural

receives data from dynamic

is constrained by control

is scaled by control

is evaluated by assurance

is monitored by assurance

Design guidance

Quantitative guidance

As stated by the sources; verify before use.

Classification

Patterns
Process isolationResource restrictionsFile system virtualizationNetwork isolationEphemeral containerizationRead-only root filesystemDefense in depthStructural containment
Technologies
Docker
Quality attributes
Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)Performance efficiency (ISO/IEC 25010)
Risks mitigated
Remote code executionContainer escapeMalicious AI-generated codeResource exhaustion / denial of serviceData exfiltrationPersistent backdoorsLateral movement
Frameworks & regulations
EU AI Act: human oversight and containment for high-risk AINIST AI RMF: isolation and containmentFDA guidance for AI-enabled medical devices

Sources

  1. Ch1.2: T. Nguyen, "Core Agent Patterns," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 1.2. ISBN: 9798244538229.
  2. Ch2.2: T. Nguyen, "LangGraph," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 2.2. ISBN: 9798244538229.
  3. Ch2.4: T. Nguyen, "Multi-Agent Frameworks," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 2.4. ISBN: 9798244538229.
  4. Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.