MOC - Adversarial Agent Containment
● Evergreen
Threat-modeling autonomous AI coding assistants, task runners, and LLM workers as unvetted junior operators with terminal access. Mitigating prompt injection breakout, accidental directory purging (rm -rf), runaway token loops, and silent git corruption.
Containment Mechanics
- Chroot & Ephemeral Namespaces: Confine worker processes to transient filesystem trees that discard completely on test failure or non-zero exit codes.
- Syscall Filtering (Seccomp): Disallow non-essential kernel system calls (
ptrace,chroot, raw socket creation) during agent execution passes. - Pre-Commit Verification Gates: Enforce automated diff inspection and test suite execution before allowing agent commits to reach the primary Git tree.
Connected Hubs & Dispatches
- [OUT-1001 - Verifying Autonomous Agent Bounds with Pure Standard Library](OUT-1001 - Verifying Autonomous Agent Bounds with Pure Standard Library)
- OUT-1002 - The Task Manifest Protocol – Explicit Authority in CI
- [BSN-1007 - Sandboxing AST Extensions with Outrigger](BSN-1007 - Sandboxing AST Extensions with Outrigger)
- [MOC - Outrigger Protocol](MOC - Outrigger Protocol)
- [MOC - Agentic Containment and Sandbox Boundaries](MOC - Agentic Containment and Sandbox Boundaries)