Talk

I Sandboxed My Coding Agents. You Should Too

Coding agents can write code, run commands, access files and interact with the network. That’s incredibly useful - and potentially a little terrifying when you give them free rein on your development machine.

In this talk, we’ll look at how to build a practical, safer development environment for coding agents on macOS. The setup starts with a minimally privileged Linux environment running in a Lima virtual machine, limiting what an agent can access if something goes wrong. But restricting the filesystem is only part of the problem. What happens when an agent can also communicate freely over the network or process untrusted content?

Building on Simon Willison’s “lethal trifecta”, we’ll explore practical ways to restrict network access, reduce the risk of data exfiltration, and let agents work more autonomously without requiring a human to approve every single action. The goal isn’t perfect isolation. It’s a development setup that makes agent-assisted coding safer by default, while remaining practical enough to actually use. Come along if you’re experimenting with coding agents, curious about their security implications, or just want to understand what happens when you give an AI agent a shell and tell it to get to work.

Date
2026-09-28
Time
18:30 - 21:00
Conference / Event
Septemberevent Ladybugs
Venue
OecherLab, Kapuzinergraben 19D, Aachen