Skip to content
Ali Akbari
Menu

Security

Hardened container arguments for agent execution

Tested in CIenvironment:LabPersonal labboundedcode-sandbox-hardening

Claim

The container runner always builds engine arguments with no network, all capabilities dropped, no-new-privileges, a non-root user, read-only mounts where requested and tmpfs masks over secret paths, and refuses sensitive host mounts such as the home directory, ~/.ssh and the Docker socket.

Status

tested
An automated test in CI asserts the claimed behaviour, including a failure case where relevant, and passes at the verified commit.
lab
Local machine, local clusters or CI runners.
personal lab
My own public repositories.

Verified commit

repository
akynte/boundedcode
release
v0.1.0-alpha.3
commit
be1aa9f87ec5ea92567d29c48bf1982ce018c227
committed
8 October 2026
CI
ci.yml #37773301609 success at be1aa9f

Curated source: paths, test names and the CI conclusion were checked against this commit by the evidence sync.

Implementation

Evidence

Environment

ci runner
GitHub-hosted ubuntu
go
1.27.1

Limitations

  • CI verifies argument construction only. The live container escape probes require Docker and are skipped in CI.
  • Isolation ultimately depends on the container runtime and host kernel.
  • Container escape resistance verified in CI: NOT VERIFIED (runtime probes run only locally).

Appears in

Related claims

Tested in CIenvironment:Lab

Containment of a prompt-injected agent

An agent that follows injected instructions cannot weaken verification — a rewritten verification config is ignored because configuration is read from the base commit and the path is protected — and a host secret behind a planted symlink never reaches a context pack.

Securityboundedcode v0.1.0-alpha.34 test files, 8 artifactsEvidence