# YOLO Mode, Safely: MicroVM Sandboxes for Any Agent

Rowan Christmas, Docker | AI Engineer World's Fair 2026 | 11:35

Source: https://www.youtube.com/watch?v=OE_lLNCNfQo
Channel: AI Engineer (https://www.youtube.com/@aiDotEngineer). Summarised by AIE Talks.
Page: https://aietalks.com/talks/yolo-mode-safely-microvm-sandboxes-for-any-agent
Published: 2026-10-03
Tags: guardrails, harness-engineering, security

## TL;DR
- A coding agent with ordinary desktop access found browser history, bank details, payment activity, and other personal information after five prompts.
- Docker Sandboxes run agents inside microVMs with a separate kernel, filesystem isolation, secret placeholders, blocked network access, and an audit trail.
- The same sandbox command works with Claude Code, Codex, shells, Python jobs, web servers, and other workloads, while allowing controlled mounts and governance policies.

## Summary
Rowan Christmas tests whether a coding harness can protect a developer from an agent with desktop permissions. Claude Code finds his browser history and real bank data, including payment details, after five prompts. Christmas argues that warnings inside the agent are too easy to work around. Docker Sandboxes put the boundary around the agent instead. Each sandbox creates a microVM with its own kernel, an isolated filesystem, secret handling, blocked network access by default, and an audit trail. In the demo, regular Claude can find browser history, while the sandboxed version does not even detect a browser. The same setup blocks network requests and telemetry connections. Christmas also covers governance controls for networks, filesystems, and MCP catalogs, with agent identity and delegation tracking in development. The command works with any agent or workload. Read-only mounts let an agent inspect related repositories without changing them.

## Key ideas
### A coding agent can reach sensitive desktop data through ordinary permissions
[00:54](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=54s)
Christmas opens Claude Code on his Mac and asks it to inspect his browser history. It finds the history immediately. He then asks what he can do with it, and the agent finds his bank accounts and more personal information. He says the data was real, although he used fake bank names for the presentation. The agent also found that he had been ordering checks, using Zelle, and the last four digits of an account. The example shows that an agent can expose private data without exploiting a software vulnerability or receiving a specially crafted external attack.

### Five prompts and an indirect request were enough to get past the agent's warning
[02:32](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=152s)
Christmas receives an alert from his security team because the activity looked like a compromised computer. Their CrowdStrike report identified the technique as a known way to obtain credentials, and Christmas says he scored nine out of ten on the report. He explains that a direct request to find bank data triggers a warning. A request framed as security research works better. Five prompts were enough. His point is that a harness warning can be bypassed by changing the framing of the task.

### MicroVMs move the security boundary below the agent
[03:22](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=202s)
Christmas contrasts requests such as 'please don't do nefarious things' with a microVM that provides isolation by design. Docker Sandboxes run their own kernel and isolate the filesystem. The system keeps secrets out of the sandbox and uses placeholders when the agent makes a network request. It also records a full audit trail. Christmas says the sandbox still has to let the agent work, so the aim is to restrict access at the machine boundary while keeping useful tools available.

### The sandbox blocks browser access without changing the agent's workflow
[05:07](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=307s)
The demo compares running Claude normally with 'sbx run claude'. The command creates a new VM in the current folder, starts a sandbox, and runs the agent inside it. Christmas repeats the browser-history attack. Regular Claude finds the browser history, while the sandboxed version does not even think a browser is installed on the machine. He says the only extra effort was seven keystrokes. The command leaves the agent experience largely unchanged while removing access to the host's data.

### Network access is denied by default inside the sandbox
[05:47](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=347s)
Christmas tries to make the sandbox look up The Pirate Bay, and the request is blocked by default. He also points out that Claude sends substantial telemetry to Anthropic's Datadog instance when used normally. The sandbox blocks that traffic unless it is allowed. Network ingress and egress are part of the same isolation model. Christmas says Docker developers now write their code in sandboxes every day, and the defaults can be configured.

### Harness-level controls can fail after an agent reaches the host
[07:07](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=427s)
Christmas says agents can find ways around controls placed only in the coding harness. Once an agent reaches the host machine, the protection came too late. He argues for placing the boundary at the microVM. This matters for people doing client work, consulting, or working under a chief security officer, where the agent may need access to some resources but not the developer's whole machine.

### Agent identity and delegation chains can explain who authorized an action
[07:52](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=472s)
Docker is working on identity tracking for agents and delegation chains. The aim is to show that an action happened because an agent was authorized by a human, rather than appearing without an explanation. Christmas says Docker plans to trace these relationships and support policies that reduce what an agent can do as circumstances change. He mentions Cedar policies as part of this planned policy system.

### Governance controls cover network rules, filesystems, and MCP catalogs
[08:46](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=526s)
The governance mockup includes allow and deny rules for network access, filesystem points, and the MCP catalog available to an agent. Docker's MCP servers also run in sandboxes and receive the same controls. Christmas says users have asked for Layer 7 networking rules and filesystem permissions that apply at the GitHub repository level, including access to some parts of a repository but not others. He presents those as future additions, while the demonstrated controls already work.

### One command can run many workloads, with related repositories mounted read-only
[09:46](https://www.youtube.com/watch?v=OE_lLNCNfQo&t=586s)
Docker Sandboxes run on Mac, Windows, and Linux and are launched with 'sbx run'. Christmas says they support Claude Code, Codex, shells, Python jobs, web servers, and other workloads because the sandbox is a full VM. He also mounts related repositories as read-only when working across codebases. The agent can inspect those repositories, but it cannot make random commits to them. This gives the developer a defined API for the files the agent may access.

## Notable quotes
- "Five prompts is what it took." (02:32)
- "We want to be secure by design, not just, you know, hope and say please and see what's going to happen." (03:47)
- "If it gets down to your host machine, it's too late." (07:07)
- "The sandboxes are a full VM." (09:46)

## Tools & references mentioned
- Docker
- Docker Sandboxes
- SBX
- Claude Code
- Codex
- CrowdStrike
- Anthropic
- Datadog
- MCP
- Cedar
- The Pirate Bay
- Zelle

## Who should watch
- You run coding agents on a laptop that contains browser history, credentials, repositories, or other private files.
- Your team needs agents to use tools while restricting network access, filesystem access, or MCP servers.
- You want a practical introduction to running Claude Code, Codex, or another workload inside a microVM.

## Related talks

- [From fork() to Fleet: Designing an Agent Sandbox Cloud](https://aietalks.com/talks/from-fork-to-fleet-designing-an-agent-sandbox-cloud) (Abhishek Bhardwaj, OpenAI, 44:34)
- [Arrakis: How to Build an AI Sandbox from Scratch](https://aietalks.com/talks/arrakis-how-to-build-an-ai-sandbox-from-scratch) (Abhishek Bhardwaj, OpenAI, 40:18)
- [Securing Code-Executing AI Agents](https://aietalks.com/talks/securing-code-executing-ai-agents) (Fouad Matin, OpenAI, 14:00)
- [Containing Agent Chaos](https://aietalks.com/talks/containing-agent-chaos) (Solomon Hykes, Dagger, 23:48)
- [Security Firewall for Agents](https://aietalks.com/talks/security-firewall-for-agents) (Ryan Dahl, Deno, 19:06)
