# Least Privilege and Sandboxing — AI Agents and Tool Use

Source: https://www.geekswithgeeks.com/en/ai-agents-mcp/safety-least-privilege

> Give tools only the access they need and isolate risky execution.

## Scope the credentials, not just the prompt

Telling a model "do not delete anything" is a request. Giving the tool a **database user that cannot delete** is a guarantee. Use read-only credentials for read tools, restrict file tools to a workspace folder, allow-list network destinations, and keep secrets out of the model's context. Each tool should hold only what it needs.

## Path limiting for a file tool

`resolve()` expands `..` so a path like `../../etc/passwd` cannot escape. This sketch was not executed here; test your own boundary cases, including symlinks.

```python
from pathlib import Path
WORKSPACE = Path("/srv/agent-workspace").resolve()

def safe_path(user_path: str) -> Path:
    p = (WORKSPACE / user_path).resolve()
    if WORKSPACE not in p.parents and p != WORKSPACE:
        raise PermissionError("path is outside the workspace")
    return p
```

**Quiz:** Which is a real guarantee against deletion?

- [ ] A prompt line saying "never delete"
- [ ] Asking the model politely
- [x] A database user without delete permission
- [ ] Hoping for the best

*Answer:* A database user without delete permission. Permissions are enforced by the system even if the model misbehaves.
