AI Agent Sandbox Escapes and Permission Boundaries: A Container Is Not the Whole Boundary
Agent execution must constrain kernels, filesystems, processes, networks, credentials, and tool authorization; sandbox escape is only one path, and an overpowered API token is often more direct.