Security
10 min readUpdated: October 2026

AI Agent Security: Sandboxing, Permission Gates & Safe Tool Execution

Technical Review: Smoke Monkey Core Architecture Team
Tested on Node.js 18+ & BunTypeScript 5.x
Quick Answer & Executive Definition

AI Agent Security: Sandboxing, Permission Gates & Safe Tool Execution: Designed as a zero-dependency, open-source TypeScript architecture under the MIT License with native Model Context Protocol (MCP) support and deterministic phase state machines.

Key Architectural Takeaways

The Three-Tier Permission Model

Smoke Monkey Harness maps every tool invocation through a configurable permission layer before execution:

  • `auto`: Execute immediately, no human prompt (safe for read-only tools like file reading).
  • `ask`: Pause and display the proposed action to the user. Resume only after explicit approval.
  • `deny`: Block the tool entirely — the agent is informed it cannot use it.

This maps directly to the principle of least privilege for agentic systems.

secure-agent.tstypescript
import { createAgent } from 'smoke-monkey-harness';
const agent = createAgent({
provider: 'anthropic',
model: 'claude-3-7-sonnet',
workspacePath: '/projects/my-app', // Sandboxed root
permissions: {
// Read tools: auto-approve
read_file: 'auto',
list_dir: 'auto',
grep_search: 'auto',
// Write tools: require human approval
write_file: 'ask',
replace_file_content: 'ask',
// Dangerous tools: always require approval
run_command: 'ask',
// Denied entirely
delete_file: 'deny',
},
});

Workspace Sandboxing

The workspacePath option in Smoke Monkey creates a hard boundary. All file operations are validated against this root:

  1. Path traversal attacks (e.g., ../../etc/passwd) are rejected before tool execution.
  2. Symlink resolution is performed before sandbox validation.
  3. Absolute paths outside the workspace are blocked automatically.

For maximum isolation, run agents in Docker containers with the workspace mounted as a volume.

Always set an explicit workspacePath

Never use process.cwd() as the workspacePath in production agents. Set it explicitly to the minimum necessary project directory.

Audit Logging Every Tool Execution

Every tool call, its input parameters, and its output are logged to the session file. Use the agent event system to pipe these logs to your SIEM or observability stack:

typescript
agent.on('tool.executed', (event) => {
  auditLogger.info({
    tool: event.data.toolName,
    input: event.data.input,
    duration: event.data.durationMs,
    approved: event.data.wasApproved,
  });
});
Google Search Questions & Answers

Frequently Asked Questions

Q:Can I allowlist specific shell commands instead of blocking all of run_command?

Yes. Use a custom tool wrapper that validates the command string against an allowlist before passing to the OS. This gives you fine-grained control over which shell operations the agent can perform.

Q:Does Smoke Monkey support network isolation for agents?

Smoke Monkey itself does not enforce network policies — use your OS-level firewall, Docker network rules, or a zero-trust proxy to restrict outbound network access from agent processes.

Related Alternatives & Comparisons

Build with Smoke Monkey Harness

Zero dependencies. 24 built-in tools. Human-in-the-loop safety. 100% open source under the MIT License.

npm install smoke-monkey-harness