Player not loading? Watch on YouTube
This Arabic-language interview is summarized in English from the complete Arabic captions. Ahmed El Imam and George Fahmy discuss how to choose a sandbox for an AI agent that can execute code or manage infrastructure. Fahmy separates prompt-based alignment from enforced restrictions: asking an agent to avoid destructive actions does not guarantee that it will comply.
His framework maps seven threat categories to seven defense layers. The discussion covers data theft, compromised dependencies, destructive operations and attacks that outlive a session. Defenses include compute isolation, resource limits, filesystem and network boundaries, credential management, action governance and audit logs. Fahmy scores enforcement strength separately from policy granularity and explains why one overall ranking can hide gaps.
The comparison examines Docker containers, Docker Sandboxes and microVMs, then considers Unikraft, Pydantic Monty and just-bash. NONO illustrates how a sandbox that runs locally can add credential and action controls inside another environment. Combining tools can improve coverage, but compatibility, configuration complexity and startup time limit that approach. Fahmy notes that his assessments use documentation, some provider conversations and partial probes; they are not exhaustive security tests.
Stakpak is presented as an open source infrastructure coding assistant that runs with access from the user's laptop, VM or cloud environment. Its Warden proxy applies policies to outgoing requests. In the closing demo, the agent eventually attempts EC2 termination, but the policy engine denies the request.