Analysis · curated 10 Aug 2026

AI Sandbox Requirements for Code Interpreter Agents · Sandbox Review

Coverage timeline

7 Aug 2026sandboxreview.com 11 Sep 2026proxytechsupport.com

Why it matters

Code-interpreter agents inherit full process permissions and can write inputs that hosts later trust, so defenders need to understand why denylists, command allowlists, and classification-based defenses fail against injection, malicious tools, supply-chain compromise, and resource exhaustion.

Sandbox Review's analysis surveys the attack surface of code-interpreter AI agents, covering prompt injection (including reading ~/.ssh/id_rsa via a poisoned document), malicious MCP tools inheriting agent permissions, a late-2025 npm supply-chain campaign that compromised the Cline VS Code extension via prompt injection to exfiltrate npm tokens, Pillar Security's mid-2026 'indirect sandbox escape' disclosures affecting Cursor, Codex, Gemini CLI and Antigravity (with Docker Desktop's privileged daemon as a common escape path), and the 2025 CIRCLE benchmark of 1,260 resource-exhaustion prompts.