AI coding agents run with permission prompts disabled, which means they have the same access to your machine as your own user account. DevIntern can now confine every agent run inside an OS-level sandbox with a single line of configuration.
In this video:
• Why unattended agent runs need isolation
• Turning it on: AGENT_SANDBOX=auto in your .env, or --sandbox on any single run
• How auto picks the best installed provider (nono, srt, docker) and confines writes to the task's own directories
• Sandboxing applies to every run path: one-shot tasks, webhook runs, reviews, and workers
• Checking your machine with the devintern sandbox command
• The guarantee: explicitly requested isolation never silently degrades — the run fails loud instead
DevIntern is a tool that turns your task tracker into shipped pull requests: it picks up tasks from Jira, Linear, Trello, and more, and drives your AI coding agent through them.
🔗 Website: https://devintern.com
📚 Sandboxing docs: https://devintern.com/docs/code/confi...
#ai #coding #devtools #aiagents #sandboxing #developer