Safety & Security · Infrastructure resource
Execution Sandbox
Infrastructure resourceSafety & SecuritySafety, Security & GovernanceVariation point (abstract)arc:ExecutionSandbox
An isolated execution environment for running untrusted, agent-generated code without exposing host systems.
Responsibility. Isolates untrusted code execution.
Also known as: Code execution sandbox, Temporary directory isolation, Docker container sandbox, Agent sandbox, Isolated execution environment
Variants
| Variant | When to choose |
|---|---|
| Dedicated Hardware Sandbox | Choose when threat modelling demands the strongest possible isolation per customer and its cost and operational complexity are acceptable. |
| MicroVM Sandbox | Choose for adversarial multi-tenant, batch or high-value workloads (e.g., financial services handling customer funds) where security outweighs VM boot latency and memory overhead; also the fallback for gVisor-incompatible workloads. |
| Shared-Kernel Container Sandbox | Choose for low-risk development environments running trusted code; insufficient for multi-tenant, sensitive-data or autonomous production workloads because of shared-kernel escape risk. |
| Syscall-Interception Sandbox | Choose when stronger isolation than standard containers is needed with modest overhead, e.g., interactive real-time services that cannot tolerate VM boot latency, provided the workload's syscalls are supported. |
Relationships
hosts structural
receives data from dynamic
is constrained by control
is scaled by control
is evaluated by assurance
is monitored by assurance
Design guidance
- MUST treat all AI-generated code as potentially hostile and execute it only inside an isolation boundary.
- MUST NOT treat sandboxing as sufficient alone; layer it with input filtering, approval gates and monitoring.
- MUST NOT replace sandboxing with code sanitization; use sanitization only as a fast first filter.
- SHOULD choose isolation strength from threat modelling rather than assuming approaches are equivalent.
- SHOULD apply production-like sandbox constraints from proof-of-concept onward to avoid disruptive retrofits.
Quantitative guidance
As stated by the sources; verify before use.
- Example resource limit: 2 GB memory and 1 CPU core per agent sandbox (Ch9.3).
Classification
- Patterns
- Process isolationResource restrictionsFile system virtualizationNetwork isolationEphemeral containerizationRead-only root filesystemDefense in depthStructural containment
- Technologies
- Docker
- Quality attributes
- Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)Performance efficiency (ISO/IEC 25010)
- Risks mitigated
- Remote code executionContainer escapeMalicious AI-generated codeResource exhaustion / denial of serviceData exfiltrationPersistent backdoorsLateral movement
- Frameworks & regulations
- EU AI Act: human oversight and containment for high-risk AINIST AI RMF: isolation and containmentFDA guidance for AI-enabled medical devices
Sources
- Ch1.2: T. Nguyen, "Core Agent Patterns," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 1.2. ISBN: 9798244538229.
- Ch2.2: T. Nguyen, "LangGraph," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 2.2. ISBN: 9798244538229.
- Ch2.4: T. Nguyen, "Multi-Agent Frameworks," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 2.4. ISBN: 9798244538229.
- Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.