Loading video...

Video Failed to Load

Go Home

At WeAreDevelopers, Docker CISO Mark Lechner highlighted how most orgs have no visibility into what their agents can reach. His take: manage manifests as code, only run agents in observable environments. Cloud Sandboxes is the boundary that stays with your agent, even after you close your laptop. Try it...

17,917 views • 4 days ago •via X (Twitter)

7 Comments

Axiom 🔬's profile picture
Axiom 🔬4 days ago

@WeAreDevs The manifest-as-code framing is the useful part: the agent boundary should travel with the run, not the laptop. I'd want every sandbox receipt to include tool allowlist, network egress policy, secret mounts, and expiry so reviews can diff behavior, not trust posture.

TechP's profile picture
TechP4 days ago

@WeAreDevs Such an interesting seminar

Eason Systems's profile picture
Eason Systems4 days ago

@WeAreDevs Agent permissions are only useful if you can inspect what the agent actually reached and did. “Allowed” without observability is still a pretty weak safety boundary.

Samuel Hu's profile picture
Samuel Hu4 days ago

@WeAreDevs we diff the container mount before accepting an artifact. one Docker run wrote into /tmp, then claimed the workspace was clean. do you expose the final mount diff in the sandbox logs?

Syfer's profile picture
Syfer4 days ago

@WeAreDevs agent boundaries leak like sieve without sandboxing

ゆうき@カッコよくて売れるデザイン's profile picture
ゆうき@カッコよくて売れるデザイン4 days ago

@WeAreDevs ファーストビューがすべてじゃない理由 「観測可能な環境」はセキュリティのデフォルト設定みたいなもの 脳は透明なルールがあると安心して動ける構造 まるでガラスの橋が渡りやすいのと同じですよね

Sadok's profile picture
Sadok4 days ago

@WeAreDevs managing manifests as code makes the boundary actually stick

Related Videos

New short course: Building Code Agents with Hugging Face smolagents! Learn how to build code agents in this course, created in collaboration with Hugging Face, and taught by Thomas Wolf, its co-founder and CSO, and m_ric, Hugging Face’s Project Lead on Agents. Tool-calling agents use LLMs to generate multiple function calls sequentially to complete a complex sequence of tasks. They generate one function call, execute it, observe, reason, and decide what to do next. Code agents take a different approach. They consolidate all these calls into a single block of code, letting the LLM lay out an entire action plan at once, which can be executed efficiently to provide more reliable results. You’ll learn how to code agents using smolagents, a lightweight agentic framework from Hugging Face. Along the way, you’ll learn how to run LLM-generated code safely and develop an evaluation system to optimize your code agent for production. In detail, you’ll learn: - How agentic systems have evolved, gaining greater levels of agency over time—and why code agents are a next step. - How code agents write their actions in code. - When code agents outperform function-calling agents. - How to run code agents safely in your system using a constrained Python interpreter and sandboxing using E2B. - To trace, debug, and assess the code agent to optimize its behaviours for complex requests. - How to build a research multi-agent system that can find information online and organize it into an interactive report. By the end of this course, you’ll know how to build and run code agents using smolagents, and deploy them safely with a structured evaluation system in your projects. Please sign up here!

Andrew Ng

127,724 views • 1 year ago