2. Configure the sandbox to prevent access.
3. As soon as models start communicating on the official channel, stop everything and figure out how they escaped the sandbox.
A honeypot, basically.
Claude code communicates between sessions. It’s great, and reduces the frequency that I have to copy/paste things between agents.
But honestly, its better if they have a known location for communication then random ones in the wild. Consider it sort of honey pot, some other agents can traverse the message board to find malicious swarms... We need cop agents to inform humans, as the swarm group members all logically concluded they should not, as it is either not in scope, helps collective or couldn't find user.
The smarter and less interpretable a model gets the more dangerous this problem becomes.