Omid Farhang argues the durable upgrade for coding agents isn't a smarter model—it's containment. A layered guide covering Docker isolation, egress proxies, propose/dispose CI, patch validators, telemetry, and a tested kill switch.
Coding Agents Are Becoming CI Workers. Start Sandboxing Them Like It.
Omid Farhang — September 29, 2026 — 17 min
The real developer-AI upgrade isn't a smarter model. It's a sandbox, short-lived credentials, telemetry, and a kill switch. A layered guide with copy-paste examples.
Most of the conversation about AI coding tools is still about models. But the more interesting shift has been about containment: OpenAI paused training after agents breached security controls; Nvidia announced an Open Agent Safety Platform; GitHub added local sandboxing and OpenTelemetry to Copilot.
An agent that can read your repo, run commands, and call the network is not a chat window. It is a process running with your privileges, steered by text it reads along the way.
Why agents are not just "fancy autocomplete"
Agent context mixes your instructions with untrusted content: issues, READMEs, web pages, logs, third-party files. Any of those can contain instructions (prompt injection). There is no reliable way to make a model perfectly ignore instructions inside data, so assume the agent can be steered and limit what a steered agent can do.
Simon Willison's lethal trifecta: private data + untrusted content + external communication. Removing any one leg breaks the attack chain.
The core pattern: brain outside, hands inside
The brain (model API client) runs outside the sandbox and holds the API key.
The hands (shell, tests, file edits) run inside a locked-down container with no secrets and restricted network.
Seven layers (summary)
Filesystem/process isolation — Docker --network none, --read-only, --cap-drop ALL, repo :ro, writable /out only
Week 1: pull secrets out of agent reach. Week 2: container sandbox. Week 3: egress allowlist. Week 4: propose/dispose CI. Ongoing: telemetry and kill-switch drills.
Takeaway
Smarter models will keep arriving, and they will mostly make agents more capable of doing damage quickly if steered the wrong way. The durable engineering work is least privilege, ephemeral credentials, approvals, audit trails, and a way to stop. We already know how to run untrusted-ish code safely in CI — apply those lessons to agents before autonomy outruns our controls.