Lesson 20 / 31

Sandboxing, Secrets and Audit Logging

Contain damage and keep evidence.

Assume something will go wrong

Design for containment. Run stdio servers in containers or sandboxes with only the folders, hosts and ports they need, as a non-root user, with resource limits. Keep secrets in a secret manager or environment injected at launch: never in tool descriptions, prompts, tool results or logs, and rotate them. Log every tools/call with timestamp, user, server, tool, arguments (redacted), outcome and approval, and alert on unusual patterns (a burst of calls, a new tool, a write at night). Keep separate environments for development and production data. Plan an emergency switch to disable a server or tool quickly.

Redact before you log

Arguments and results may contain personal data or secrets. Mask them before they reach your log store.

Quick check: What does running a server in a sandbox achieve?

  • Makes the server faster
  • Limits what a compromised or buggy server can reach
  • Removes the need for approval
  • Encrypts the model
Answer

Limits what a compromised or buggy server can reach — Containment bounds the damage of any failure.