CONNECTED THINKING

Knowledge atlas

Follow people, viewpoints and their original evidence.

1 people · 1 sources · 1 viewpoints

IN CONTEXT

agent security risk

Choose a viewpoint. Follow it back to the conversation.

Agent harness in same Sandbox creates lethal trifecta

IN CONTEXTagent security risk1 viewpoints
2026-10-01

Equal sectors are reading positions, not rankings.

Showing 1–1 of 1 viewpoints · Newest sources first

1 / 1

Selected viewpoint

Agent harness in same Sandbox creates lethal trifecta

Johnston cites Simon Willison’s “lethal trifecta”: access to private data, exposure to untrusted content and the ability to communicate externally can allow a tricked agent to leak data. She says a coding agent whose harness runs in its Sandbox has all three by default.

These are individual perspectives, not a measure of consensus. Source material stays in its original language.

Supporting evidence

Sidecars: A low-latency trust boundary for Sandboxes | Modal Blog

Original excerpt

Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
Context

Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..

Publication dates describe the sources, not changes in belief.