The mechanism
“Sandbox” is not a single isolation guarantee. A component may mediate operations inside one process, execute commands in an existing container, connect to a remote host or create a stronger virtualized boundary. The name alone does not tell you which files, network paths, credentials or kernel interfaces are reachable.
Strands Shell’s official security model calls it a mediation layer rather than a hardened sandbox. Its boundary applies to operations initiated inside that shell, not unrelated tools registered with the same agent. The SDK’s DockerSandbox adapter executes against an already running container; it does not itself create Docker Sandboxes microVMs. Keep these products and guarantees distinct.
A worked boundary comparison
| Mechanism | What to inspect | What not to assume |
|---|---|---|
| Strands Shell | Bound paths, network policy, credential mediation | That other agent tools inherit its controls |
| SDK DockerSandbox | Existing container, user, mounts, network and host access | That the adapter creates a microVM |
| Remote execution adapter | Remote identity, host policy and transport | That “remote” implies isolated |
| Docker Sandboxes product | Workspace mode, microVM, engine and network policy | That shared writable files cannot affect the host |
This is a reasoning aid, not a certification table. Follow each product’s current documentation and test the actual deployment configuration. The companion Docker Sandboxes handbook develops the microVM and workspace model in more depth.
Practice: trace a file write
Offline architecture exercise. Draw an agent with two tools: a mediated shell and a direct Python function that writes a local file. The shell is configured to expose only a fixture directory. Where does the direct Python function write?
Expected observation: the shell’s policy does not automatically constrain arbitrary code in another tool. A secure design must review every execution path. Remove the direct writer or place the whole process inside an appropriate execution boundary with scoped mounts and credentials.
Now trace a container adapter that mounts a host project read-write. A write inside the container can change that shared project. Container placement does not make the mount harmless. Use disposable fixtures for tests, and never mount sensitive host directories or the Docker socket merely to make a lesson convenient.
A proposed verification record
{
"execution_kind": "not_selected",
"runtime_version": null,
"workspace_mode": null,
"allowed_paths": [],
"allowed_destinations": [],
"credential_scope": "none",
"negative_tests": [],
"status": "design_only"
}
Populate this record only from observed configuration and permitted tests. An empty allowed-destinations list here is a template value, not evidence that a real runtime blocks all egress. Record the test method and result separately from the desired policy.
Troubleshooting and trade-offs
If a command cannot find a file, determine which filesystem it is actually using before broadening mounts. If a network request fails, separate name resolution, routing, policy and application response. If a credential is missing, prefer a scoped integration over copying a broad host environment into the execution process.
Stronger isolation can increase startup cost and operational complexity. Choose it according to the threat model: trusted narrow functions, untrusted generated code and multi-tenant workloads have different needs. State residual risks and avoid describing one successful negative test as proof of complete isolation.
Interview practice
Does adding a safe shell tool constrain every other tool?
No. Its mediation applies to its own operation path. Other tools retain their own permissions and security properties unless a broader process or runtime boundary constrains them.
Why distinguish SDK DockerSandbox from Docker Sandboxes?
The SDK adapter targets an existing container, while Docker Sandboxes is a separate product with its own runtime and workspace model. Similar names do not establish equivalent isolation.
Completion check
Trace one read, write, network call and credential use through the actual boundary. Identify a bypass path created by another tool and redesign it. Keep all runtime experiments disposable and explicitly authorized.
Sources and version notes
Checked 6 October 2026. Python examples target strands-agents==1.58.0 unless labelled otherwise. Live documentation can change; compare your installed version before adapting an example.
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.