The Sandbox — Give Your Agent a Disposable Code-Exec Sandbox
Vibe Coding Nights #42 — The Sandbox, a Saturday-morning build sprint in the Off the Leash season. Never run an agent's code on your host: box it, snapshot it, nuke it. The threat case for untrusted agent-written code as its own category (destructive, exfil, persistence) with five real incidents, then the four isolation options side by side — Docker, e2b, Daytona, gVisor — on what each actually isolates, start latency, and cost, landing on sandbox-per-task as the default. Three hands-on labs: stand up your first box, point your agent at it, then snapshot / trash / restore / nuke. 17 slides with URL-hash deep links, five runnable stdlib-first examples, agent-readable /llms.txt and a .well-known/ai-agent.json that carries the verbatim prompt that built the deck. The deck itself was built live in about 30 minutes by 12 agents across 4 terminals coordinating through an Immersive Commons agent room.