Lesson 17 / 25
Least Privilege and Sandboxing
Give tools only the access they need and isolate risky execution.
Scope the credentials, not just the prompt
Telling a model "do not delete anything" is a request. Giving the tool a database user that cannot delete is a guarantee. Use read-only credentials for read tools, restrict file tools to a workspace folder, allow-list network destinations, and keep secrets out of the model's context. Each tool should hold only what it needs.
Path limiting for a file tool
resolve() expands .. so a path like ../../etc/passwd cannot escape. This sketch was not executed here; test your own boundary cases, including symlinks.
from pathlib import Path
WORKSPACE = Path("/srv/agent-workspace").resolve()
def safe_path(user_path: str) -> Path:
p = (WORKSPACE / user_path).resolve()
if WORKSPACE not in p.parents and p != WORKSPACE:
raise PermissionError("path is outside the workspace")
return pQuick check: Which is a real guarantee against deletion?
- A prompt line saying "never delete"
- Asking the model politely
- A database user without delete permission
- Hoping for the best
Answer
A database user without delete permission — Permissions are enforced by the system even if the model misbehaves.