MOC - Adversarial Agent Containment

● Evergreen

Threat-modeling autonomous AI coding assistants, task runners, and LLM workers as unvetted junior operators with terminal access. Mitigating prompt injection breakout, accidental directory purging (rm -rf), runaway token loops, and silent git corruption.

Containment Mechanics

  • Chroot & Ephemeral Namespaces: Confine worker processes to transient filesystem trees that discard completely on test failure or non-zero exit codes.
  • Syscall Filtering (Seccomp): Disallow non-essential kernel system calls (ptrace, chroot, raw socket creation) during agent execution passes.
  • Pre-Commit Verification Gates: Enforce automated diff inspection and test suite execution before allowing agent commits to reach the primary Git tree.

Connected Hubs & Dispatches

  • [OUT-1001 - Verifying Autonomous Agent Bounds with Pure Standard Library](OUT-1001 - Verifying Autonomous Agent Bounds with Pure Standard Library)
  • OUT-1002 - The Task Manifest Protocol – Explicit Authority in CI
  • [BSN-1007 - Sandboxing AST Extensions with Outrigger](BSN-1007 - Sandboxing AST Extensions with Outrigger)
  • [MOC - Outrigger Protocol](MOC - Outrigger Protocol)
  • [MOC - Agentic Containment and Sandbox Boundaries](MOC - Agentic Containment and Sandbox Boundaries)