Skip to main content

Unexpected Agent Code Execution

Keep model output, tool arguments, generated code, interpreters, and sandboxes from becoming uncontrolled host execution.

Threat

Unexpected agent code execution occurs when model output or untrusted tool data reaches a shell, interpreter, template engine, notebook, build system, browser automation surface, package manager, or dynamic evaluator with more authority than intended. It also includes generated code escaping its sandbox or invoking hidden host capabilities.

Tool invocation is data exchange until an executor interprets the data. Define that boundary explicitly.

Isolate execution

Avoid general code execution when a small typed operation can perform the task. Use fixed command and argument mappings. Do not concatenate model text into shell, SQL, templates, paths, or code. Validate paths against a dedicated working root and block traversal and link escape.

When execution is required, use an ephemeral isolated environment with a read-only base, no host socket, no inherited credentials, limited files, memory, CPU, process count, time, and network. Supply only task-specific input and output channels. Destroy the environment after the task and scan outputs before another trusted system consumes them.

Failure and residual risk

A language sandbox can expose native extensions, system calls, browser APIs, package installation, or network. An allowlisted command can accept an argument that loads code or writes outside the workspace. Generated artifacts can carry scripts or formulas into later tools. A sandbox escape turns the runner identity and network reach into attacker authority.

Isolation reduces impact. It cannot make hostile code safe. Keep high-value credentials and control planes outside the reachable environment.

Pomerium boundary

Pomerium can authenticate and authorize access to an execution service route. It does not sandbox commands, generated code, or tool processes. The execution service owns input handling, isolation, credentials, network, filesystem, resource limits, output inspection, and teardown.

Evaluation checklist

  • Can a typed operation replace general interpreter or shell access?
  • Are model and tool strings never concatenated into executable contexts?
  • Does the execution environment have no host socket or inherited credential?
  • Are filesystem, network, process, time, memory, and output boundaries enforced outside the model?
  • Can traversal, package install, fork, network, secret read, and sandbox escape tests fail safely?

Sources and further reading

Keep learning

Agentic AccessAuthorization and Policy

Tool Misuse

Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.

Learn this term
Agentic AccessSecurity Operations and Risk

Tool Surface Area

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Blast Radius

Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo