AI Agent Security: Sandboxing, Permission Gates & Safe Tool Execution
AI Agent Security: Sandboxing, Permission Gates & Safe Tool Execution: Designed as a zero-dependency, open-source TypeScript architecture under the MIT License with native Model Context Protocol (MCP) support and deterministic phase state machines.
- Three-tier permission model: auto-approve, ask, or always-deny per tool
- Workspace sandboxing prevents writes outside the configured root
- Every tool execution is logged with full input/output audit trail
- Allowlist specific shell commands to block dangerous operations
The Three-Tier Permission Model
Smoke Monkey Harness maps every tool invocation through a configurable permission layer before execution:
- `auto`: Execute immediately, no human prompt (safe for read-only tools like file reading).
- `ask`: Pause and display the proposed action to the user. Resume only after explicit approval.
- `deny`: Block the tool entirely — the agent is informed it cannot use it.
This maps directly to the principle of least privilege for agentic systems.
import { createAgent } from 'smoke-monkey-harness';const agent = createAgent({provider: 'anthropic',model: 'claude-3-7-sonnet',workspacePath: '/projects/my-app', // Sandboxed rootpermissions: {// Read tools: auto-approveread_file: 'auto',list_dir: 'auto',grep_search: 'auto',// Write tools: require human approvalwrite_file: 'ask',replace_file_content: 'ask',// Dangerous tools: always require approvalrun_command: 'ask',// Denied entirelydelete_file: 'deny',},});
Workspace Sandboxing
The workspacePath option in Smoke Monkey creates a hard boundary. All file operations are validated against this root:
- Path traversal attacks (e.g.,
../../etc/passwd) are rejected before tool execution. - Symlink resolution is performed before sandbox validation.
- Absolute paths outside the workspace are blocked automatically.
For maximum isolation, run agents in Docker containers with the workspace mounted as a volume.
Always set an explicit workspacePath
Never use process.cwd() as the workspacePath in production agents. Set it explicitly to the minimum necessary project directory.
Audit Logging Every Tool Execution
Every tool call, its input parameters, and its output are logged to the session file. Use the agent event system to pipe these logs to your SIEM or observability stack:
agent.on('tool.executed', (event) => {
auditLogger.info({
tool: event.data.toolName,
input: event.data.input,
duration: event.data.durationMs,
approved: event.data.wasApproved,
});
});Frequently Asked Questions
Q:Can I allowlist specific shell commands instead of blocking all of run_command?
Yes. Use a custom tool wrapper that validates the command string against an allowlist before passing to the OS. This gives you fine-grained control over which shell operations the agent can perform.
Q:Does Smoke Monkey support network isolation for agents?
Smoke Monkey itself does not enforce network policies — use your OS-level firewall, Docker network rules, or a zero-trust proxy to restrict outbound network access from agent processes.
Related Alternatives & Comparisons
Build with Smoke Monkey Harness
Zero dependencies. 24 built-in tools. Human-in-the-loop safety. 100% open source under the MIT License.