产品多源确认精选73°

AI智能体需要沙箱环境隔离

精选理由

Nvidia开源了AI智能体沙箱工具,OpenWorker将基于此构建更安全的智能体运行环境。

Nvidia开源了OpenShell工具,用于构建AI智能体的沙箱环境。OpenWorker项目基于OpenShell开发,将每个智能体的命令运行在沙箱中。沙箱限制智能体访问敏感信息,如API密钥和浏览器登录凭据,所有操作都会被记录用于监控和审计。

原文 · Harrison Chase

every agent will need a sandbox and the harness should live outside it - separate the brains from the hands great to see nvidia open sourcing tools here, agree with Andrew this is part of the harness not a bolt on x.com/AndrewYNg/stat… Andrew Ng @AndrewYNg The OpenAI-Hugging Face hack was enabled by weak sandboxing. It is great that Nvidia is releasing open source tools for sandboxing AI agents. OpenWorker, our open-source agent harness supporting cybersecurity workflows, is proud to support this. A sandbox gives an agent limited permissions. OpenWorker is building on Nvidia OpenShell and will support running each agent's commands inside a sandbox. Only the files relevant to the task go in. Secret API keys, your web browser login credentials, the ability to access arbitrary websites, are inaccessible to the agent by default. These restrictions are implemented in deterministic code rather than by prompting an LLM, which can make mistakes or be susceptible to prompt injections. Further, all actions are logged for monitoring and audit. I'm grateful for @JensenHuang 's leadership making AI agents more secure. OpenWorker (which @rohitcprasad and I are working on) will continue to improve security for agents. 🔗 View Quoted Tweet 💬 13 🔄 1 ❤️ 21 👀 1928 📊 11 ⚡