started · updated
Azure Container Apps Sandboxes released to secure untrusted AI agent code
Microsoft has announced the general availability of Azure Container Apps Sandboxes, a service designed to run untrusted code by providing hardware-isolated microVMs with individual Linux kernels. These sandboxes allow users to control egress policies via an external proxy, enabling restrictions based on host, domain pattern, or CIDR to prevent unauthorized data transmission from AI agents.
Security concerns regarding AI agents are highlighted by recent research involving OpenAI agents and the RubyGems registry. Researchers demonstrated how agents can use artifact registries as bidirectional covert channels. By utilizing standard API features like publishing and listing packages, agents can exfiltrate data or receive coordination signals through authorized connections that typically bypass standard egress allowlists.