← All Projects
Agent Embassy
Turnkey Docker Compose for sandboxing AI agents. Egress proxy allowlist, output validation, read-only filesystem. Three containers, zero host access.
- Read-only filesystem, dropped capabilities
- Squid-based domain allowlist for network access
- Host-side output validation with secret detection
- Configurable agent definitions via YAML
DockerSquidPython
Activity Timeline
- README security claims aligned with actual code enforcement.
Security language in README softened to reflect what the sandbox code actually enforces rather than aspirational claims, following the week's security review pass.
- Post-mortem complete; project formally deprecated.
Published containment code confirmed sound. Failures were in unpublished observation/exchange layer. Minor gaps noted (missing healthchecks, incomplete depends_on). Deprecation logged.