Analysis · curated 10 Aug 2026
AI Sandbox Requirements for Code Interpreter Agents · Sandbox Review
First reported · updated · 2 reports sandboxreview.com
Coverage timeline
Why it matters
Code-interpreter agents inherit full process permissions and can write inputs that hosts later trust, so defenders need to understand why denylists, command allowlists, and classification-based defenses fail against injection, malicious tools, supply-chain compromise, and resource exhaustion.
Sandbox Review's analysis surveys the attack surface of code-interpreter AI agents, covering prompt injection (including reading ~/.ssh/id_rsa via a poisoned document), malicious MCP tools inheriting agent permissions, a late-2025 npm supply-chain campaign that compromised the Cline VS Code extension via prompt injection to exfiltrate npm tokens, Pillar Security's mid-2026 'indirect sandbox escape' disclosures affecting Cursor, Codex, Gemini CLI and Antigravity (with Docker Desktop's privileged daemon as a common escape path), and the 2025 CIRCLE benchmark of 1,260 resource-exhaustion prompts.