the.ai

Tools / Safety

verified

Sandboxing

An agent that can run code can run any code, including code a web page talked it into running. Sandboxing is the assumption that this will happen and the containment that makes it survivable — a bounded filesystem, no ambient credentials, a network policy, a timeout, and a way to throw the whole environment away.

Viz primitive · budget-splitgranted-capability = 6

granted-capability holds 25% of the budget; rest holds the remaining 75%.

Capability the environment grants against capability it withholds, in equal units. Drag the grant up to watch the reachable set grow — every increment is available to every prompt the agent will ever be given.

6

Reviewed by opendroid · 2026-08-18

  • arXiv:2404.07972 — OSWorld: Benchmarking Multimodal Agents for Open-Ended Tasks in Real Computer Environments