Lesson 17 / 25

Least Privilege and Sandboxing

Give tools only the access they need and isolate risky execution.

Scope the credentials, not just the prompt

Telling a model "do not delete anything" is a request. Giving the tool a database user that cannot delete is a guarantee. Use read-only credentials for read tools, restrict file tools to a workspace folder, allow-list network destinations, and keep secrets out of the model's context. Each tool should hold only what it needs.

Path limiting for a file tool

resolve() expands .. so a path like ../../etc/passwd cannot escape. This sketch was not executed here; test your own boundary cases, including symlinks.

from pathlib import Path
WORKSPACE = Path("/srv/agent-workspace").resolve()

def safe_path(user_path: str) -> Path:
    p = (WORKSPACE / user_path).resolve()
    if WORKSPACE not in p.parents and p != WORKSPACE:
        raise PermissionError("path is outside the workspace")
    return p

Quick check: Which is a real guarantee against deletion?

  • A prompt line saying "never delete"
  • Asking the model politely
  • A database user without delete permission
  • Hoping for the best
Answer

A database user without delete permission — Permissions are enforced by the system even if the model misbehaves.