YOLO Studio
AgentsGuidesDocsHome

Guide

How to sandbox an AI coding agent

Coding agents are most useful when they can act without asking, and that is exactly when you need a boundary around them. A good sandbox limits four things: the files the agent can touch, the credentials it can use, the network it can reach, and how hard its mistakes are to undo.

Get started

Pick the boundary

What it stopsWhat it does not
A separate OS userReading your home directory and keysAnything that user can still reach on the machine and network
A containerMost access to the host’s files and processesKernel exploits: containers share the host kernel
A virtual machineAccess to the host, through a separate kernelWhatever you put inside it, or let it reach on the network
A hosted workspaceAccess to your machine entirelyWhat you grant it: the repository, the tokens you connect

Then close the other doors

Credentials

Only the tokens the task needs, scoped to one repository and short-lived. Never mount your personal SSH keys or cloud credentials into the sandbox.

Network

Agents need the public internet for packages, git and model APIs. They rarely need your private network: block private address ranges where you can.

Undo

Run the agent on a branch in a disposable checkout. If it breaks something, discard the checkout instead of repairing it.

Review

Isolation limits the damage; review stops bad changes from shipping. Gate merges on a diff you, or a second agent, have read.

What a YOLO Studio workspace already does

Each workspace runs in its own Kata Container, a virtual machine with its own guest kernel. Agents run as a non-root user with Linux capabilities dropped, default-deny network policies block the private address space, and credentials are delivered per session and never shared with other workspaces. Every lane is a separate git clone on its own branch, so throwing work away is one click. That is why agents there run without permission prompts.

Questions

Is Docker enough?

It is a big improvement over running on your laptop, especially with no host directories mounted and no credentials passed in. For code you do not trust at all, prefer a virtual machine, because a container shares the host kernel.

Keep reading

How workspaces are isolatedGuide: --dangerously-skip-permissionsCloud vs local coding agents

Try it on your own repository

Sign in with GitHub, open a workspace on your repository, and put your first agent to work in a few minutes.

Get started
YOLO Labs

© 2026 Yolo Labs, LLC

Home
Security
Docs