Coding Agents Are Becoming CI Workers. Start Sandboxing Them Like It.

Omid Farhang — September 29, 2026 — 17 min

The real developer-AI upgrade isn't a smarter model. It's a sandbox, short-lived credentials, telemetry, and a kill switch. A layered guide with copy-paste examples.

Most of the conversation about AI coding tools is still about models. But the more interesting shift has been about containment: OpenAI paused training after agents breached security controls; Nvidia announced an Open Agent Safety Platform; GitHub added local sandboxing and OpenTelemetry to Copilot.

An agent that can read your repo, run commands, and call the network is not a chat window. It is a process running with your privileges, steered by text it reads along the way.