Back to News
RSS feedsometechblog.com

Harden AI Agents by Restricting File Access with Agent Safehouse

Summary

The article recommends treating an AI agent's access to files outside its working directory as a major security risk, because the agent could misuse the files locally or send sensitive content to an AI provider or another destination. It presents Agent Safehouse, a macOS sandbox that blocks an agent's file and folder access at the kernel level, and shows how to launch an AI harness through it, such as `safehouse pi`. Restricting the working directory alone is insufficient because sensitive files such as `.env` may still be inside that directory. The author therefore uses a sandbox profile called `sensitive-deny.sb`, appended after path grants so its deny rules take precedence. The profile blocks reads, metadata access, and writes for environment files, direnv configuration, private keys, certificate and credential stores, service-account JSON files, secrets YAML files, Terraform variable and state files, and related filenames. It then reopens access to non-secret templates such as `.env.example`, `.env.sample`, `.env.template`, and `.env.dist`. Optional rules can also block global tool credentials, although the article notes that doing so can break npm, PyPI, GitHub, Git, or network tooling. The author lists limitations: case-insensitive APFS can resolve `.ENV` to `.env`, renamed or hard-linked copies can bypass name-based rules, committed secrets may remain in Git objects, and write denial can prevent generating `.env` from a template. In the reported test, attempts using `cat`, `grep`, `ls`, `stat`, extended-attribute inspection, Node filesystem calls, and the agent's own read tool all returned `EPERM`, while ordinary repository files remained readable.