Running coding agents locally, do you sandbox them or trust them?
Developers running coding agents like Claude Code or Codex locally are concerned about security. They are exploring methods to limit agent access to their systems, considering options such as dev containers, separate user accounts, or full VMs. Each method has drawbacks, like shared kernels in containers or the inconvenience of VMs. The community is discussing whether any agents have caused destructive actions and what preventative measures were taken.
Unlike general discussions about AI safety, this thread focuses specifically on practical, local sandboxing methods for coding agents and their real-world limitations.
Time & source
Times shown in UTC
Display time zone: UTC
Local time zone unavailable; showing UTC.
PublishedOffset at this time: UTC+0Oct 8, 2026, 22:12 UTC
IngestedOffset at this time: UTC+0Oct 9, 2026, 06:00 UTC
- Published
- Oct 8, 2026, 22:12
- Ingested
- Oct 9, 2026, 06:00
- Source type
- Dev community
- Tier
- Community
- Source status
- Sync delayed
Tier is a per-source editorial setting, not a per-item score.
Discussion trend
The percentage is based on collected discussion signal, not new comments or independent people. The curve only compares the same topic across time.
For people running Claude Code, Codex, or local-model agents against their own machine... how are you limiting what they can touch?
The options I've seen are a dev container, a separate user account, a full VM, or just watching closely. Each one leaks somewhere (containers share the kernel, VMs are annoying, and watching doesn't scale past an afternoon).
We went with a microVM that only sees the workspace you share, plus a policy check on each tool call. There's a free desktop tool on our side if anyone wants to compare notes, but mostly I want to know where people draw the line between convenience and isolation.
Has anyone had an agent actually do something destructive? What did you change afterward?