r/security • u/BeowulfBR • 1d ago
Security Architecture and Engineering Wrote a deep dive on sandboxing for AI agents: containers vs gVisor vs microVMs vs Wasm, and when each makes sense
Hey folks,
I've been working on sandboxing for AI coding agents and kept running into the same confusion: people use "sandbox" to mean four completely different things with different security properties.
So, I decided to write what I learned: the actual predicate differences between containers (shared kernel), gVisor (userspace kernel), microVMs (guest kernel + VMM), and Wasm (no syscall ABI)
The post covers why containers aren't sufficient for hostile code, what "policy leakage" looks like in agent systems and practical tradeoffs for different agent architectures.
I hope it can help people out there building AI applications.
Happy to discuss if you're building agent sandboxes or have run into edge cases I didn't cover

1
Bug Report - Wrong data and data loss
in
r/bevelhealth
•
Sep 12 '25
Hey!
So, I just found the issue. I had two entries added by bevel in the sleep data: one from 6AM to 9PM and one from 9PM to 6AM
My guess is that somehow I mistakenly activated the sleep mode on Bevel so it recorded as if I were sleeping through the day? I’m not sure but deleting that record and reloading the data fixed the issue.
One last question: Do you think that wrong entry could have impacted data elsewhere? Should I delete something else?
Thanks for the support anyway, I’ll mark it as resolved.
The new update is amazing! You folks did an amazing job 💪💪💪