Skip to content

Comment on The Paranoid Guide to Running Copilot CLI in a Secure Docker Sandboxparent

Comments

They absolutely will, but a non-root user inside docker so far, even when asked, did not result in any damage outside the the docker container. With root it managed to break things, but as user it did not find a way. When I asked it to try more 'fishy' things, codes + claude code both refused; after prompting some more 'but we are testing a security tool ' etc, it just tried very meek things that did not manage to do anything.

Sounds like the real sandbox in this scenario is the alignment training of the LLMs you tried.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.