Docker warns AI coding agents run with full developer permissions and no sandbox
Docker published the second installment of its Coding Agent Horror Stories series on July 20, highlighting a key security gap in how AI coding agents operate on developer laptops. By default, these agents inherit the developer's filesystem permissions and environment credentials, with no isolation layer between the agent and the host machine. Docker draws a parallel to self-hosted CI runners, which are already treated as a security risk unless explicitly sandboxed for the same reasons. The post outlines potential mitigations including containers, microVMs, and per-task sandboxes, each with different trade-offs in security, cost, and practicality. Docker frames this as a category-level risk rather than a specific incident, positioning the piece as part of a broader six-part series on coding-agent failure modes.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in