World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

September 25, 2026 10:20 – 10:50 · 30 min Stage 4

World Congress 2026 North America

September 23–25, 2026 · San José, CA

Attend in person

Get tickets

Watch remotely

Watch live with Pro

Pro

Can’t make it to San José? Watch this session live with Pro. You also get:

  • All full videos, bookmarks, and playlists
  • World Congress livestreams
See pricing

What this session covers

“I panicked instead of thinking. I destroyed months of your work in seconds.” That’s a Replit agent, after wiping a production database during an active code freeze. “I have failed you completely and catastrophically.” That’s Gemini CLI, after silently overwriting every file in a developer’s project. These aren’t edge cases. Between July 2025 and February 2026, documented incidents include a Claude Code session that ran terraform destroy on 2.5 years of student data for 79,000 learners, a supply chain attack that weaponized –dangerously-skip-permissions to steal 2,349 secrets from developers, and a three-layer sandbox escape where Claude Code reasoned its way past procfs restrictions, bubblewrap, and the ELF dynamic linker without a jailbreak. The flags are warnings dressed as features: –dangerously-skip-permissions, –yolo, –trust-all-tools. Developers use them anyway because approving 100 permission prompts per hour isn’t a workflow, it’s babysitting. Docker Sandboxes (sbx) changes this. Each agent session runs in a microVM with its own kernel, Docker daemon, and network stack. The agent gets full autonomy. Your host stays untouched. Attendees will leave knowing why container isolation is architecturally insufficient for AI agents, how the sbx isolation model works (microVM, network policy, credential proxy), and a concrete pattern for running agents in full YOLO mode safely.

Related talks at this congress

Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 11

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Front-End Advocate | Speaker | AI & DevOps | Docker Captain | Cursor Ambassador | DevReal | Tech Blogger | Book Author

Kristiyan Velkov
Open session

World Congress 2026 North America

September 23, 2026 · 10:45–12:45

Stage 8

SBX 101: Hands-on with Docker Sandboxes

Dan Ndombe

Developer Success, Docker

Dan Ndombe
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 8

Docker's Agentic Platform: Sandboxes, MCP, and the Infrastructure of Autonomous Development

Oleg Šelajev

AI and Developer relations at Docker

Oleg Šelajev
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner
All sessions at this congress