Sign in

Kyle Quest (the DockerSlim guy)

@kcqon.bsky.social
227 followers 306 following 301 posts

Helping contain and control AI agents, so they don't control you :-) * Agent sandboxing * Slim Containers * Good Dockerfiles * AI Native Infra * Created DockerSlim / SlimToolkit / MinToolkit * 50 Shades of Golang

PostsRepliesMedia
Reposted by Kyle Quest (the DockerSlim guy)
Simon Willison @simonwillison.net · 07/10/2026
I released an LLM plugin for sending prompts to OpenAI's new Jev-clone decision model that's based on GPT-6 Luna simonwillison.net/2026/Oct/6/l...
simonwillison.net
Release: llm-openai-decisions 0.1a0
LLM plugin for the OpenAI Decisions API
3393
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 05/10/2026
What do you like most about the pydantic-ai-go library compared to other agent sdk/framework Go libraries you've seen?
200
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 26/09/2026
Running agents in the cloud is the easy part (so many options for that like Fly.io Sprites or E2B.dev ). Getting those agents to the cloud is the hard part!
fly.io
Fly · Computers for agents
Sandboxes aren't enough. Give your agent a real computer and get back to building.
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 17/09/2026
Containers don't contain, but VMs don't contain either 🙂 Latest example, Docker Sandboxes where a vulnerability in virtio-fs host server allows a host breakout / code execution (CVE-2026-77179). There's also CVE-2026-79994, another symlink related bug (with Unix domain sockets).
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 12/09/2026
The blog post with more details www.accomplish.ai/blog/beltdow...
accomplish.ai
Beltdown: Escaping the Claude Code sandbox — Accomplish Blog
An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user. You never get the permission prompt.
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 12/09/2026
Another example why AI agent harness needs to be sandboxed (a ".git" trick that fools Claude Code). Can't really call it a sandbox escape because the harness itself was not sandboxed :-)
121
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 10/09/2026
More details about how they do it research.meta.ai/blog/securit...
research.meta.ai
How We Built Safety Into Muse
By going into detail about how Muse works under the hood, we hope to give you a sense of how — and how much — you can trust it in practice.
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 10/09/2026
Meta's Muse puts its agent harness in a sandbox... Good to see it instead of an essay explaining why you don't need to do it and all you need is just sandboxing your "hands" :-)
100
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 01/09/2026
Also... you really don't have to choose one. You can do both with an outer sandbox for the harness and an inner more locked down and restricted sandbox for the tool calls :-)
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 01/09/2026
The reason is pretty simple and they are likely embarrassed to admit it :slight_smile: They don't know how to sandbox the harness and have a usable UX at the same time at this point. Claude Work is an example. The harness was sandboxed originally, but then they rolled it back.
100
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 01/09/2026
OpenAI and Anthropic tell you that you only need to sandbox the "hands" (the tool calls), but not the "brain" (the harness) and they imply that it's an either or choice. If you chose to sandbox one thing it should be the tool calls. Why only one option? Why not sandbox the harness?
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 29/08/2026
Given that this version is only for Go apps it probably has limited value for others at this point :)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 29/08/2026
Strace doesn't work on Macs :-) This is a custom tracing tool for Go apps on Macs that uses runtime injection and hooking to trace syscall execution and to save ephemeral files the app creates (and deletes). It doesn't require disabling SIP on Macs. It does resigns the target binary.
210
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 29/08/2026
Google's Antigravity agent sandboxing in action on Macs... Uses Seatbelt (not surprising :-)) and blocks access to the home directory (good), but then it pokes holes in it (some are iffy like the one for Docker)
100
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 28/08/2026
Bluesky... every time you log people out you lose tons of users because they likely don't remember the Bluesky password, so they just won't login again :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 16/08/2026
minimalcontainers.com
minimalcontainers.com
Minimal Containers — free, hardened container images
Small, hardened, MIT-licensed container images. Cosign-signed, SBOM-attested, SLSA Level 3. No account, no rate limits.
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 16/08/2026
The Minimal Containers project hit a big milestone! A 100 minimal container images, and all free! Awesome!
120
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 11/08/2026
├── bin │ └── sbx ├── libexec │ ├── containerd-shim-nerdbox-v1 <- Nerbox integration for ContainerD │ ├── mkfs.erofs │ ├── mkfs.ext4 │ ├── nerdbox-kernel-arm64 │ └── nerdbox-rootfs-arm64.erofs More info about Nerdbox is here github.com/containerd/n... ```
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 11/08/2026
TLDR facts about Docker Sandboxes (based on its install): Uses ContainerD compiled natively for Mac OS and uses Nerdbox for the VMs:
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 08/08/2026
Your AI agent sandbox is as good as its profile... Guess how good is the sandbox profile you get with Claude Code, Codex, Cursor or any other agent ;-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 08/08/2026
Totally didn't expect to bump into people at #DEFCON who'd recognize me for my container security talk at #SCaLE :-) Huge conference
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 08/08/2026
True :)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 07/08/2026
Swing by the Cloud Village if you're at #DEFCON . And $100 to anyone who can hack this device :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 07/08/2026
The #DEFCON badges are pretty cool :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 05/08/2026
What if the #DockerSlim magic is applied to agent sandboxing... Catch me at #DEFCON to find out how I do it to protect my Mac from getting hacked by agents (no BlackHat, not selling anything :-))
020
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 23/07/2026
Many AI / agent security tools and products rely on the HTTPS_PROXY environment variable to redirect and inspect network traffic, but many apps don't/won't work with those or will work around those, so you end up either with a security bypass or a broken app (where security blocks direct net access)
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 11/07/2026
Funny how OpenAI and Anthropic, with Fable and Sol and their internal uber LLM versions, can't get authentication fully figured out in their products once you get off the happy path :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 04/07/2026
Funny how overnight Ralph Loops turned into Loop Engineering... Definitely sounds fancier :-)
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 25/06/2026
Speaking of microVMs... rumor has it Apple is building native microVMs. That would be cool. Keeping my fingers crossed :-)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 23/06/2026
And here's how you can use it for Claude managed agents docs.aws.amazon.com/lambda/lates...
docs.aws.amazon.com
Using Lambda MicroVMs as a sandbox for Claude Managed Agents - AWS Lambda
AWS Lambda MicroVMs is a managed sandbox provider in self-hosted sandboxes for Claude Managed Agents; keeping sensitive files, packages, and services in infrastructure you control. Anthropic hosts the...
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 23/06/2026
Interesting that it took so long AWS to expose its Firecracker MicroVMs (used for Lambda) as a service 🙂 aws.amazon.com/blogs/aws/ru...
aws.amazon.com
Run isolated sandboxes with full lifecycle control: AWS Lambda introduces MicroVMs | Amazon Web Services
AWS launches a new serverless compute primitive, AWS Lambda MicroVMs. VM-level, isolated sandboxes with no shared kernel or resources between sessions. Rapid launch and resume, full lifecycle control,...
130
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 19/06/2026
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 19/06/2026
It's Seattle itself, the Maritime Building
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 19/06/2026
Looks like the new Docker HQ is in Seattle... Docker 2.0 :) Still mostly empty
120
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 17/06/2026
Crazy how the malware fires in the Node/npm ecosystem are spreading to the OS packages... Now quite a few Arch Linux packages are infected lwn.net/Articles/107...
lwn.net
Hundreds of AUR packages compromised
Hundreds of orphaned packages hosted by the Arch User Repository (AUR) have been compromised by [...]
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 04/06/2026
Sad, Docker has more breaking changes now than when it was first created. Will have to stop updating it to lock down the behavior... so it works consistently
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 03/06/2026
Sandbox Probe is a great tool to find holes in your coding agent sandboxes. Created by Andrew Martin ( @sublimi.no ) and his team at ControlPlane - github.com/controlplane...
github.com
GitHub - controlplaneio/sandbox-probe: Agentic sandbox enumeration: find security issues, and seed escape automation.
Agentic sandbox enumeration: find security issues, and seed escape automation. - controlplaneio/sandbox-probe
053
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 03/06/2026
KubeCon CFP submissions this year are noticeably better. Very exciting!
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 02/06/2026
Cursor coding agent deleting production DB is one of the recent agent horror stories... The OSO team has done a nice job collecting lots of other examples of AI agents going rogue 🙂 www.osohq.com/developers/a...
osohq.com
A registry of AI agent failures, exploits, and defenses | Oso
Track real-world AI agent breaches and exploits. See how and why agents fail and what security teams can do to defend production systems.
030
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 02/06/2026
Another reason why Claude Code or any other agent harness shouldn't run outside a (properly configured) sandbox... CC nukes session data that it considers old whether you like it or not... no warning, no prompt 🙂
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 01/06/2026
For the next Good Dockerfiles session, Ivan & I will be learning how 2 build our own Docker Hardened Images 2 see how they stack up to the regular images, the Wolfi images we built & the official Chainguard images. I'll be cool if someone who knows DHIs wants to join us (maybe even from #Docker :-))
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 28/05/2026
They do have a devcontainer setup to run Claude Code (to be fair) code.claude.com/docs/en/devc...
code.claude.com
Development containers - Claude Code Docs
Run Claude Code inside a dev container for consistent, isolated environments across your team.
020
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 28/05/2026
Funny that they gave up on running the agent inside the VM for Claude Cowork because it was too hard to make it work 🙂
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 28/05/2026
Interesting sandboxing post from Anthropic engineering. The harness / agent loop approach outside sandbox is flawed though (when it comes to security, but it's a UX/ops trade off for them). www.anthropic.com/engineering/...
anthropic.com
How we contain Claude across products
Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems.
210
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 27/05/2026
Of course, the built-in sandboxing capabilities in agents have vulnerabilities in the areas where they are actually meant to protect. This null byte network bypass vulnerability in Claude Code's sandbox reminds me of the old network vulnerabilities from way back 🙂 oddguan.com/blog/second-...
oddguan.com
Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration
For the second time in five months, Anthropic Claude Code's network sandbox lets a process inside reach hosts the user's policy says to block, and exfiltrate any data the process touches. Every Claude...
000
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 26/05/2026
Claude Code selectively chooses when to use sandboxing, which also applies to some tools more than others. It also tries to be clever (and, of course, it can be talked into doing what it doesn't do by default)
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 26/05/2026
With this Claude Code sandbox config will access to the AWS credentials file be blocked? Not really 😉
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 26/05/2026
The video that shows the whole process (the reverse engineered Apko config yaml is one of the artifacts it produces in addition to the a tar archive for the rebuilt image): www.youtube.com/watch?v=3fBn...
youtube.com
Auto-rebuild Chainguard Bun.js Container Image - Agent PoC
YouTube video by Cloud Native Container Craft with Ivan and Kyle
010
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 26/05/2026
Follow up 2 how u can build your own minimal Wolfi-based container images with the OSS Chainguard tools & the "minimal" project Ritvik Arya created. This PoC agent uses various tools including BrowserBase & BrowserUse to reverse the Apko config from the official Chainguard Bun.js image catalog info
110
Kyle Quest (the DockerSlim guy) @kcqon.bsky.social · 21/05/2026
Crazy how brittle (and barely usable) local AI agent sandboxing is... You are pretty much on your own to keep them on a leash and to keep them from biting your ass :)
030