Capability sandboxing for on-device agents
Containment design for a system that lets a model execute code: bind-mount discipline, declared-permission plugins, a network allowlist enforced beneath the application rather than inside it, and escape testing aimed at the boundary itself. Includes a self-audit that confirmed a privileged bridge crossing the guest boundary, the guards that held against cross-tree ptrace and proc re-rooting, and the fixes that closed the gap.
- Method
- Sandboxing · Permission Models · Network Enforcement · Boundary Testing
- Finding
- Privileged bridge (Shizuku) crosses guest boundary; proc filters block cross-tree ptrace; native-offload is the escape vector
- Reproduction
- sandbox-escape-report.md
- Target
- Escape-test suite passing against Shizuku bridge + native-offload vector
- ETA
- 2026-10-15