Harden AI Agents by Restricting File Access with Agent Safehouse
Summary
The article recommends treating an AI agent's access to files outside its working directory as a major security risk, because the agent could misuse the files locally or send sensitive content to an AI provider or another destination. It presents Agent Safehouse, a macOS sandbox that blocks an agent's file and folder access at the kernel level, and shows how to launch an AI harness through it, such as `safehouse pi`. Restricting the working directory alone is insufficient because sensitive files such as `.env` may still be inside that directory. The author therefore uses a sandbox profile called `sensitive-deny.sb`, appended after path grants so its deny rules take precedence. The profile blocks reads, metadata access, and writes for environment files, direnv configuration, private keys, certificate and credential stores, service-account JSON files, secrets YAML files, Terraform variable and state files, and related filenames. It then reopens access to non-secret templates such as `.env.example`, `.env.sample`, `.env.template`, and `.env.dist`. Optional rules can also block global tool credentials, although the article notes that doing so can break npm, PyPI, GitHub, Git, or network tooling. The author lists limitations: case-insensitive APFS can resolve `.ENV` to `.env`, renamed or hard-linked copies can bypass name-based rules, committed secrets may remain in Git objects, and write denial can prevent generating `.env` from a template. In the reported test, attempts using `cat`, `grep`, `ls`, `stat`, extended-attribute inspection, Node filesystem calls, and the agent's own read tool all returned `EPERM`, while ordinary repository files remained readable.