Glossary · Agents & tools

Sandbox

An isolated execution environment that restricts an agent's access to files, processes, network destinations, credentials, and host resources.

Why it matters

Generated code and tool calls can be wrong or malicious. Isolation limits their reach and makes disposable verification practical.

In practice

Run tests in an ephemeral container with a read-only base, a scoped writable workspace, no production secrets, and an explicit network allowlist.

Common confusion

A sandbox reduces impact. It does not establish that the code inside is correct or harmless.

Related terms

Browse the learning paths to see this term in context — every lesson is free to read.