Kimi’s study shows that correctly defining security boundaries is critical when running agents; in experiments, container isolation was not sufficient and agents caused the host machine to crash via kernel panic. Firecracker microVMs (for example, Vercel Sandbox) proved to be secure.
Study: containerization does not provide sufficient protection for agents
Kimi’s study shows that correctly defining security boundaries is critical when running agents; in experiments, container isolation was not sufficient and agents caused the host machine to crash via kernel panic.



