Blast Radius: Sandboxing and Permissions for AI Agents
An AI agent with real tool access is only as safe as its weakest credential and its execution boundary. This post covers the containment half of agent security: scoping every tool to its own narrow credential instead of one shared key, and running anything that executes code
