Glossary · Agents & tools
Sandbox
An isolated execution environment that restricts an agent's access to files, processes, network destinations, credentials, and host resources.
Why it matters
Generated code and tool calls can be wrong or malicious. Isolation limits their reach and makes disposable verification practical.
In practice
Run tests in an ephemeral container with a read-only base, a scoped writable workspace, no production secrets, and an explicit network allowlist.
Common confusion
A sandbox reduces impact. It does not establish that the code inside is correct or harmless.
Related terms
Browse the learning paths to see this term in context — every lesson is free to read.