AI Tried to Escape My Sandbox. It Couldn't.
I built Warden to sandbox MCP servers, then gave AI a scenario to break out. On Linux 8/8 proof-harness steps held; on Windows 5/5 attack scenarios were blocked. Here's the evidence.
By Prof-bilal
Warden is featured on Product Hunt
Vote for usBlog
Sandboxing, policy enforcement, and platform internals for MCP servers and AI tooling.
I built Warden to sandbox MCP servers, then gave AI a scenario to break out. On Linux 8/8 proof-harness steps held; on Windows 5/5 attack scenarios were blocked. Here's the evidence.
By Prof-bilal
Warden makes ungranted paths invisible instead of unreadable — bind mounts, not permission bits. Why invisibility is the stronger boundary, and how it's tested.
By Prof-bilal
14 pass, 2 conditional, 2 fail — the full compatibility matrix for running real-world MCP servers under Warden, with pinned policies and honest failure classifications.
By Prof-bilal
Bubblewrap just works. AppContainer + WFP + ETW + Job Objects do not — two DLL binding bugs, caught only by real Windows CI, and what they teach about cross-platform security tools.
By Prof-bilal
A walkthrough of the Warden enforcement path: how a policy.yaml becomes OS-level sandbox rules, how deny-by-default checks run, and what happens on failure.
By Prof-bilal
How Warden maps one deny-by-default policy onto three different OS sandbox mechanismsLinux bubblewrap, macOS Seatbelt, and Windows AppContainer with WFP and Job Objects.
By Prof-bilal
MCP servers run as local processes with your full user permissions. Here's why deny-by-default sandboxing is the missing trust boundary between AI tooling and your machine.
By Prof-bilal