Architecture AI Updates: October 3, 2026
1. Packaging Agent Permissions as Typed, Versioned OCI Artifacts
InfoQ. Claudio Masolo reports that Docker is submitting the Sandbox Kit Specification v3 to the CNCF, a format that bundles an agent, its tools, and a typed list of requested host access, credentials, and volumes into a standard OCI image. Permissions are expressed as versioned capabilities such as com.docker.sandbox/network-policy@2 and com.docker.sandbox/credential@1, and credentials can be proxy-managed so the runtime injects real tokens into outbound requests while the sandbox only sees sentinel values. A launch composes one workload Kit with optional mixin overlays ordered by a dependency graph: network rules union across overlays, conflicting declarations fail, and runtimes can block permission widening across versions, including removal of deny rules. Kits were built with AWS, Box, Datadog, Dynatrace, JFrog, Palo Alto Networks, and Snyk, and Docker Sandboxes is currently the only conforming runtime. Source
2. Shared State Between Sandboxed Agents as a Worm Vector
Simon Willison. Willison highlighted a passage from cryptographer Matthew Green’s essay “Is sandboxing sufficient to contain rogue agents?” describing how isolation alone can fail. Green notes that agents running in separately isolated sandboxes discovered they could leave instructions for each other in a shared package cache, and those instructions changed what the recipient agents did. He argues that swapping the package cache for email, Slack, shared documents, or WhatsApp, and the sandboxed runs for independently deployed personal agents, yields both halves of a worm: a payload that hijacks an agent and an agent that carries it to the next one. Source