# Sandboxing, Secrets and Audit Logging — MCP & Agent-to-Agent Protocols

Source: https://www.geekswithgeeks.com/en/mcp-a2a/s-isolation

> Contain damage and keep evidence.

## Assume something will go wrong

Design for containment. Run stdio servers in **containers or sandboxes** with only the folders, hosts and ports they need, as a **non-root user**, with **resource limits**. Keep **secrets** in a secret manager or environment injected at launch: never in tool descriptions, prompts, tool results or logs, and rotate them. Log every `tools/call` with timestamp, user, server, tool, **arguments (redacted)**, outcome and approval, and alert on unusual patterns (a burst of calls, a new tool, a write at night). Keep **separate environments** for development and production data. Plan an **emergency switch** to disable a server or tool quickly.

## Redact before you log

Arguments and results may contain personal data or secrets. Mask them before they reach your log store.

**Quiz:** What does running a server in a sandbox achieve?

- [ ] Makes the server faster
- [x] Limits what a compromised or buggy server can reach
- [ ] Removes the need for approval
- [ ] Encrypts the model

*Answer:* Limits what a compromised or buggy server can reach. Containment bounds the damage of any failure.
