upvote
This is the only kind of agent security that makes sense to me. Constrain it like you would any other subprocess. Unprivileged OS users, SELinux, firewalls, VMs... Unikernels? eBPF?
reply
Escalations to root are a dime the bucket.
reply
That argument is letting the perfect be the enemy of the good.

There is no perfect security.

reply
Me too.
reply