Agent Application DevelopmentAccount
Knowledge catalogChoose core direction and segmented content
Practice 48AdvancedSystem designAbout 18 minutes

Corresponding knowledge: Isolate resources and capabilities when executing code

Let the Agent execute Python or Shell, what needs to be isolated in the production sandbox?

Examine files, networks, processes, credentials, and resource limits.

Sandboxcode executionPermission isolation

Knowledge content check2026-10-03 · Check the source of the original question2026-10-02

Knowledge unit directory

LEARN · PRACTICE · REFLECT

Knowledge exercises·Independent answers

My notes and review ↗

Principles and Solutions have been collapsed. Explain the core mechanism, boundaries and verification methods in your own words, and then compare them.

Answers and personal notes

Each modified commit will be kept as an independent history. Your level of mastery is up to you to evaluate yourself against the standards.

Explain in your own words first

The core principles, analysis, Q&A and migration cases have been closed. When you are ready, unfold it and compare it with the content to find any omissions.

Hands-on verificationComplete on demand · Suggestions15 minutes

Write a least-privilege manifest and kill process for tasks that only require reading CSV and generating charts.

Expand acceptance requirements and checkpoints
  • No extraneous networks and secrets
  • Bounded resource and process tree cleanup
  • Product export checked

Key inspections

  • Isolation covers multiple resource areas
  • Credentials and networks have minimum scope
  • Timeout cleanup process tree and artifact exit