Sidecars:沙箱的低延迟信任边界|Modal 博客
西蒙·威利森(Simon Willison)将其称为“致命三重组合”:一个能够访问私有数据、接触不可信内容,并具备对外通信能力的智能体,可能被诱骗而泄露该数据。一个运行于沙箱(Sandbox)中的编码智能体,其执行环境(harness)默认即同时具备这三种特性。
原始摘录
Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
上下文
将执行环境(harness)与工具调用(tool calls)共同托管存在安全风险:执行环境的凭据与生成的代码并置;智能体可从网络(例如软件包和代码仓库)读取不可信内容;且沙箱内任何内容均可发起网络请求。
原始上下文
Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..