Skip to main content

AI coding · Security

Sandboxed Execution

Also called: Sandbox, Isolated execution, Code sandbox

Run AI-generated code or commands in an isolated environment with limited network, filesystem, and secret access to reduce accidents and supply-chain risk.

In detail

A sandbox separates "can run" from "can touch real data." Scripts, installs, and tests suggested by an AI are dangerous on a developer laptop or production host: they might delete files, read .env, or call unknown hosts.

Common shapes: containers, VMs, no-network CI jobs, iframe previews. Products that let models run commands should default to sandbox + human confirmation.

It isn't magic: overly broad mounts or secrets copied into the sandbox still hurt. Least privilege is the rule.

Developer info
Term ID
ai-sandbox
DOM selectors
No DOM cues. This concept isn't detected directly on a page.
Priority
1 · when several match at the same level, the higher priority wins
Version
v1 · updated Oct 5, 2026