AI News Nuggets

Agent safety needs clear tool boundaries across local and cloud models

Microsoft is bringing local-model choices and sandboxed tool execution to GitHub Copilot, while AWS's Strands Box preview combines operating-system containment with policies that can consider an agent's action history.

Editorial read

This edition collects 2 notes across 2 topic areas and 2 sources. Start with Local inference changes where a model runs, not what its agent tools can reach, Agent policies should consider action history and make coverage gaps explicit to get the week's main practical signal before scanning the remaining links.

Edition signal

The October 10 signal is to govern model routing and tool execution as separate decisions

Microsoft describes local and cloud model selection for GitHub Copilot alongside Microsoft Execution Containers for tool sandboxing. Automatic routing is planned by the end of October, while sandbox enforcement varies between shell commands, built-in file tools, and remote MCP connections. AWS's Strands Box developer preview combines operating-system containment with Dogwood policies for selected tool and network actions; directly granted file paths do not enter its policy history. Neither announcement proves a complete security boundary for every agent integration. Before expanding an agent workflow, document where inference and data may go, what each tool can reach, which actions are checked by the operating system or the harness, and how to test denied actions and revoke access.

AgentsSecurityTools
Security
Official AWS Strands Box developer-preview announcement

Agent policies should consider action history and make coverage gaps explicit

Source: AWS

AWS has released Strands Box in developer preview, starting on macOS. It combines operating-system containment with Dogwood policies evaluated at network, shell, Python, and MCP enforcement points. Those checks can use a shared action history, such as blocking outbound requests after a sensitive file read. AWS says file paths granted directly to the agent are bounded by containment but do not appear in that policy history, so policy coverage depends on how the agent reaches a resource.

Why this matters: Map every action path before treating one policy file as comprehensive. Define the agent's workspace, outbound destinations, credential handoff, and allowed tool operations, then test sequences that cross tools, such as reading sensitive data followed by an HTTP call. Include direct file access and remote tools in the review because they may follow different enforcement paths. Strands Box is a preview and begins on macOS; evaluate its actual coverage and failure behavior in a bounded environment before making a production control claim.

Read AWS's Strands Box announcement