Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Sandboxing limits where an AI agent’s code can run; access controls limit what that code can reach. They are complementary safeguards, not substitutes. An agent can interact with files, credentials, tools, and network destinations exposed by its environment, so enforce limits in the operating system and trusted application layers—not just in a prompt.
What sandboxing and access restriction each do
A sandbox is an execution boundary: it can constrain the files, processes, and other resources available to agent-directed code. Access restriction is the broader policy governing which files, tools, credentials, data, and network destinations the agent may use. A sandbox does not automatically make every exposed resource safe, and an access policy is only effective if the environment and application enforce it.
OpenAI’s sandbox security guidance warns that code generated or directed by an agent can access the files, credentials, and network available to its environment. Treat those capabilities as real even when the agent has been instructed not to use them.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsHow to sandbox an AI agent
- Define the workload boundary. Decide which user, task, or workload owns the environment. Use separate environments when users or workloads must not share data. If they share an environment, treat its files, credentials, and other resources as shared access.
- Choose an execution boundary that fits the risk. Do not treat a working directory,
HOME, orcwdas confinement. OpenAI’s Agents SDK sandbox client guide says its Unix-local Linux backend runs commands as host processes and adds no OS-level confinement. Use a suitably configured Docker or hosted sandbox, or another external isolation mechanism, for untrusted commands. The local macOS backend applies filesystem restrictions but does not provide network isolation or the same boundary as a container. - Limit the sandbox’s filesystem and privileges. Expose only the workspace and files needed for the task. Avoid admin or
sudoprivileges by default, and do not allow an agent to grant itself more privileges. Make database access read-only unless a specific task requires writes. - Set network policy deliberately. Disable outbound access if the workflow does not need it. Otherwise, permit only approved destinations and consider where tool connections originate. Restricting a sandbox’s network does not necessarily constrain connections made by tools or services outside it.
- Keep valuable secrets outside the execution environment. Do not put application API keys or broadly usable third-party credentials where agent-directed code can read them. A trusted broker or vault-backed proxy can provide narrowly scoped access for approved destinations without exposing the underlying secret to the code.
- Keep the harness separate from execution. The agent harness can retain model calls, tool routing, approvals, audit and tracing, recovery, and run state in trusted infrastructure while sandbox compute executes commands and manipulates files. A sandbox is most useful when work needs commands, packages, artifacts, exposed services, a workspace, or resumable state; a short response without persistent execution may not need one.
- Test and monitor the controls. Before production, test third-party tools and generated scripts in hardened environments with syscall and network-egress restrictions where appropriate. Monitor execution and review permissions, mounts, network rules, and connector configuration.
How to stop an AI agent from accessing files or secrets
Files and shared workspaces
Mount or expose only the files needed for the task, and separate environments when users or workloads must not see one another’s data. A workspace path is a convenience, not a security boundary: a host process may still access other resources permitted by the host. OpenAI’s self-hosted guidance also notes that agents sharing an environment can access the same files, credentials, and other resources; the operator must configure isolation rather than assume it.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Application and third-party credentials
Keep application credentials in trusted infrastructure rather than the execution container. For third-party access, use a broker or vault-backed proxy that checks the destination and attaches a narrowly scoped credential outside the sandbox. OpenAI documents this pattern for hosted sandboxes: code can see a placeholder while a proxy supplies a real secret only for approved hosts. On self-hosted infrastructure, the operator must provide the trusted proxy or server.
Tools, connectors, and data
Apply least privilege to the agent’s role and each tool operation. Prefer read-only access where practical, restrict sensitive personal data, and do not allow the agent to modify its own privileges. Connected applications can expand effective access beyond the sandbox: OpenAI warns that users may access data or perform actions through a creator’s personal app connections. Limit who can use such agents, avoid sensitive or high-impact connectors where possible, and audit their configurations.
Rank #2
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Shared memory
Shared agent memory is a separate access and integrity risk. AWS guidance describes it as dynamic and potentially difficult to validate with conventional database constraints. Treat retrieved memory as partially trusted: limit who can modify it, validate information before acting on it, and consider a deterministic gateway for centralized filtering, integrity checks, policy enforcement, and audit trails.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →How to restrict an AI agent’s network access
Start with no egress when the task can run without network access. If it needs access, allow only the domains or endpoints required, and review whether requests originate from the sandbox, a tool, or a separate service. A prompt asking an agent to avoid a destination does not block network traffic.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
OpenAI’s hosted-sandbox documentation describes three network modes: outbound access can be enabled, disabled, or restricted to listed domains. It says access is enabled by default unless an inherited template policy applies. These are documented behaviors of that product, not assumptions to make about other hosted or self-hosted systems.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choosing a local, containerized, hosted, or self-hosted setup
Compare the actual boundary and operating responsibilities, not the label “sandbox.” The table distinguishes common deployment approaches; the exact guarantees depend on configuration and provider.
Rank #4
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
| Approach | Execution boundary | Network and credentials | Separation and operations |
|---|---|---|---|
| Local execution | On OpenAI’s Unix-local Linux SDK backend, commands are host processes with no OS-level confinement. Its macOS backend restricts filesystem access but does not provide network isolation or a container-equivalent boundary. | Resources permitted to the host may be reachable; workspace settings do not establish isolation. Configure external controls if the workload is untrusted. | Runs on the operator’s machine. Do not assume a separate environment per user or workload. |
| Containerized execution | A configured container can provide an execution boundary; the real guarantee depends on its configuration and the host. | Set filesystem mounts, privileges, and network egress explicitly; keep valuable secrets outside the container. | The operator configures and maintains the container and its isolation. A container alone does not prove users or workloads are separated. |
| OpenAI-hosted sandbox | Provider-managed sandbox compute; OpenAI documents a separate workspace for each session. | Documented network modes allow outbound access, disable it, or restrict it to listed domains. Vault credentials keep real secrets outside the sandbox. | OpenAI documents per-session workspaces; provider-managed infrastructure does not remove the need to scope permissions and connections. |
| Self-hosted sandbox | The operator chooses and configures the laptop, container, or remote sandbox; the name alone does not establish a boundary. | The operator must isolate execution, scope environment credentials, keep the application API key out of the sandbox, and provide any trusted credential proxy. | Offers operational control, with responsibility for setup, patching, isolation, monitoring, and audit. Shared environments share access to their resources. |
For any option, verify six things before deploying: the enforced OS or virtualization boundary; filesystem mounts and per-workload separation; egress policy and connection origin; whether code can read real credentials; whether roles and permissions are narrow and reversible; and who patches, monitors, and audits the infrastructure.
Quick Recap
Best Value
- Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
- USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Deployment checklist
- Separate users and workloads that must not share data.
- Do not rely on prompts, workspace paths,
HOME, orcwdas security boundaries. - Use an appropriately configured container, hosted sandbox, or external isolation for untrusted execution.
- Expose only necessary files, tools, data, and permissions; avoid admin privileges and unnecessary database writes.
- Disable network egress when possible; otherwise allow only required destinations.
- Keep application and third-party secrets outside the execution environment; broker narrowly scoped access.
- Review connector permissions, shared memory write access, and agent audience.
- Test and monitor tools and generated scripts, and audit environment configuration regularly.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

