Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restrict a local AI agent by limiting what its process can reach—not by relying on a prompt. Give it only the files and credentials required for the task, run it as an unprivileged user inside an OS-enforced sandbox or VM, and enforce outbound network rules outside the agent. Then test that allowed access works and everything else is denied.

Why the agent’s execution environment is the security boundary

An agent that can run code may be able to use the files, credentials, tools, and network routes available to its process. OpenAI’s agent security guidance recommends isolated compute and cautions against sharing an environment across unrelated users or trust boundaries. Treat the agent like any other program that can execute code: its effective permissions determine what it can access.

A prompt, an agent’s own tool allowlist, or an HTTP proxy environment variable may help guide or constrain behavior, but none is a hard boundary by itself. Use operating-system permissions, a sandbox or VM, and network controls enforced outside the agent. Keep credentials outside the workspace wherever possible.

Choose an isolation approach

These approaches can be combined. Agent-native controls are useful for limiting ordinary tool behavior, while an OS-enforced environment supplies a separate boundary if the agent or generated code behaves unexpectedly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
MINISFORUM MS-02 Ultra Workstation Mini PC, Intel Core Ultra 9 285HX (24C/24T, up to 5.5GHz), PCIe 5.0 x16, 32GB RAM 1TB SSD,USB4 v2 80Gbps, Dual 25GbE+10GbE+2.5GbE, Wi-Fi 7, 350W PSU
  • High-Performance AI Processor:The MS-02 Ultra features an Intel Core Ultra 9 285HX (24C/24T, up to 5.5 GHz, 13 TOPS NPU), delivering fast and efficient performance for AI inference, algorithm development, and media workloads. A PCIe x16 expansion slot supports desktop-class GPU upgrades for advanced model training and accelerated computing tasks. It's ideal for creators, engineers, and teams handling intensive parallel workloads.
  • 4 × M.2 PCIe 4.0 + 4 × DDR5 SODIMM slots:Four DDR5 SODIMM slots support up to 256 GB of memory, while ECC helps maintain data integrity in mission-critical environments. Four PCIe 4.0 M.2 slots support up to 24 TB of storage, supporting RAID 0/1/5/10, combining high-speed performance with data protection. It allows for the creation of independent scratch disks, media libraries, and project drives, providing high-throughput for production workflows.
  • PCIe & USB 4.0 v2: Up to three PCIe slots can be equipped, including a dual-slot x16 GPU. The main slot supports PCIe 5.0, meeting the needs of high-bandwidth creative and computing workloads. USB 4.0 v2 (80Gbps) supports high-bandwidth external storage and displays.
  • Ultra-fast Networking: Wi-Fi 7 further enhances wireless performance with next-generation speeds and low-latency stability. Intelligent bandwidth switching optimizes throughput in different network environments, ensuring optimal performance for enterprise or local networks. Dual 25GbE ports (providing up to approximately 3.125 GB/s bandwidth, about 25 times faster than traditional 1GbE), enabling seamless large-scale file transfers and parallel computing. 10GbE and 2.5GbE ports, with support for Intel vPro technology, ensure enterprise-grade remote management and deployment flexibility.
  • Server-grade thermal architecture: Utilizing a dedicated CPU/GPU airflow design, equipped with a 6-pipe dual-fan cooler, it maintains stable performance even under sustained loads, delivering up to 140W Turbo power while maintaining a 100W TDP, and operating with noise levels as low as 36 dB. An integrated 350W power supply ensures stable and reliable output for demanding computing tasks and fully loaded extended configurations.
Approach Filesystem control Network control Secrets and host services Trade-offs
Agent-native permissions Product-level controls, such as directory scope or tool allow/deny settings; not a replacement for OS permissions. Depends on the product and configuration; verify whether egress is blocked outside the agent. Credentials available to the agent process may remain accessible. Host-local services depend on the process’s network access. Often simplest to configure, but its protection depends on product behavior and does not independently constrain arbitrary code.
Container or devcontainer Can limit visible files through mounts and OS permissions; avoid mounting broad host directories. Can be paired with network policy, but default-deny behavior depends on the runtime and its configuration. Keep secrets out of mounts; reaching host services may require explicit network configuration. Usually integrates with development workflows, but host integration and isolation details vary by setup.
VM-based sandbox Provides a separate environment; expose only the workspace and other required files. Can enforce egress restrictions at the VM or host network layer. Keep credentials outside the VM unless needed; configure deliberate access to any host service. Creates stronger separation from the host, with added setup and possible compatibility costs.
Managed or self-hosted sandbox Can expose selected filesystems or mounts; exact controls are product-specific. Some configurations support controlled external access; check the product’s actual policy and defaults. OpenAI’s self-hosted sandbox guidance says to keep the application API key outside the sandbox. Host-service access depends on the deployment. May provide purpose-built controls, but requires product-specific configuration and verification.

Docker’s Sandboxes documentation describes isolated agent environments and network policy configuration. In Docker’s local-model walkthrough, the sandbox needs an explicit policy rule to reach a model served on the host. That example is specific to its setup, not a universal default for other sandbox products.

Set up a restricted agent environment

  1. Choose the trust boundary. Run code-executing agents in a dedicated VM, container sandbox, or other OS-enforced environment. Do not put unrelated work or sensitive host data inside it. Anthropic’s managed sandbox material recommends separating workspaces and environments where trust boundaries differ.
  2. Expose a narrow workspace. Mount or grant access to just the repository or task directory. Do not expose an entire home directory by default. Add other directories only when the task requires them. For example, Claude Code’s CLI reference documents --add-dir for additional working directories; this product control does not replace OS-level file permissions. See the Claude Code CLI reference.
  3. Use an unprivileged identity. Run the agent under a dedicated account or sandbox identity without elevated host privileges. Restrict writes to the workspace and explicitly designated scratch locations. Anthropic describes project-scoped writes in its Claude Code security guidance and suggests devcontainers as another layer; define the outer boundary with OS and sandbox policy.
  4. Deny network access by default, then allow required destinations. Permit the inference endpoint and only the endpoints needed by enabled tools. Enforce this at the firewall, VM, or sandbox network layer rather than assuming the agent will comply. If you route traffic through a proxy, verify that direct connections are blocked too: OpenAI’s Windows endpoint hardening article notes that software can bypass environment-based proxy settings when it does not honor them.
  5. Keep credentials separate. Do not mount SSH directories, cloud credential files, password stores, or production secrets into the workspace. If a task genuinely requires authenticated access, use a broker or narrowly scoped temporary credentials. OpenAI’s self-hosted sandbox guidance specifically advises keeping the application API key outside the sandbox.
  6. Test and review the effective policy. Confirm that the agent can read and write the files it needs, and that out-of-scope files and blocked network destinations are inaccessible. Revisit the policy when you change the model provider, MCP servers, plugins, enabled tools, or CLI version. Product documentation describes available controls; it does not establish that a particular local setup is correctly configured.

Allow only the network traffic the task needs

Build the allowlist from the actual components enabled in your setup: the inference provider, and any tool services the task needs. Avoid copying a vendor’s endpoint list as a universal rule. For example, Anthropic’s proxy documentation lists api.anthropic.com, statsig.anthropic.com, and sentry.io for the setup it describes. Those hosts are not necessarily the complete or appropriate list for another deployment, provider, or tool configuration.

Check whether the agent must reach local services, too. A model listening on the host may not be reachable from an isolated sandbox unless you deliberately allow the connection. Docker’s local-model walkthrough demonstrates adding a specific rule for a host-local endpoint. Grant such an exception only when needed, and keep it as narrow as the sandbox’s policy supports.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use agent permissions as an additional layer

Agent interfaces can reduce accidental actions and make a setup easier to operate, but distinguish them from controls that constrain the process independently. Claude Code documents directory and tool controls in its CLI reference, including --add-dir, tool allow/deny flags, and --dangerously-skip-permissions. Understand the effect of the flags for the installed version; a tool-level setting does not create an OS-enforced filesystem or network boundary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
GMKtec EVO-X2 AI Mini PC Ryzen Al Max+ 395 Superchip 128GB LPDDR5X 2TB SSD
  • EVOLUTION RYZEN AI MAX+ 395 MINI PC - GMKtec EVO-X2 is the next evolution in AI mini PC Ryzen Strix Halo series. Thanks to AMD Simultaneous Multithreading (SMT) the core-count is effectively doubled, to 32 threads. Ryzen AI Max+ 395 has 64 MB of L3 cache and can boost up to 5.1 GHz, depending on the workload. The Ryzen AI Max+ 395 is currently rated as the "most powerful x86 APU" on the market for AI computing.
  • AI NPU with XDNA 2 ARCHITECTURE - Powered by 16 “Zen 5” CPU cores, 50+ peak AI TOPS XDNA 2 NPU and a truly massive integrated GPU driven by 40 AMD RDNA 3.5 CUs, the Ryzen AI MAX+ 395 is a transformative upgrade and delivers a significant performance boost over the competition. The Ryzen AI Max+ 395 excels in consumer AI workloads like the llama.cpp-powered application: LM Studio. Shaping up to be the must-have app for client LLM workloads, LM Studio allows users to locally run the latest language model without any technical knowledge required and unleash their creativity and productivity.
  • AMD RADEON 8090S iGPU GAMING PC - The AMD Radeon RX 8060S offers all 40 CUs with up to 2.9 GHz graphics clock and uses the new RDNA 3.5 architecture. The powerful iGPU is positioned between an RTX 4060 and 4070 laptop GPU and therefore enables gaming in FHD at maximum details in most demanding games. The 8060S can also utilize the full 128GB pool, which is perfect for running LLMs such as Deepseek 70B Q8, which runs comfortably on this machine.
  • EIGHT CHANNEL LPDDR5X - LPDDR5X is a new ground breaking memory small form factor installed on-board. With blazing speeds up to to 8000MT/s, it runs 1.5x faster than the DDR5 SODIMMs; 90% better performance over DDR5 SODIMMs in video conferencing and photo editing; 30% better performance in productivity apps; 12% better performance in digital content workloads.
  • QUAD SCREEN 8K DISPLAY SUPPORT - EVO-X2 AI Mini PC support 4-screen 4K/8K output via HDMI 2.1 (8K@60Hz), DisplayPort 1.4 (4K@60Hz), and dual USB 4 40Gbps Transfer speed (supporting PD3.0/DP1.4/DATA). Ideal for gaming, video editing, and multitasking, it provides expansive and crisp multi-display support.

Likewise, do not rely on proxy variables alone to prevent egress. A program that ignores those variables can make direct connections unless the surrounding network policy blocks them. Use agent-level settings for usability, and an independently enforced sandbox, OS, or network rule for containment.

Check product behavior and version before relying on it

Controls and defaults vary by product, release, platform, and configuration. OpenAI’s Codex Help Center describes Full Auto as sandboxed, network-disabled, and scoped to the current directory, but that description may not match every current installation. Verify behavior against the Codex Help Center guidance and the official documentation for the version you run.

Docker’s Claude Code sandbox tutorial says the first sandbox run asks for a default network policy and recommends reviewing workspace, network, and credential access. Follow the current documentation for your installed release rather than assuming another version or product has the same defaults.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.