<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sandbox on Mathias WOLFF</title><link>https://www.blog-des-telecoms.com/tags/sandbox/</link><description>Recent content in Sandbox on Mathias WOLFF</description><generator>Hugo</generator><language>fr</language><copyright>&lt;a href="https://www.blog-des-telecoms.com">Blog des télécoms&lt;/a> © 2009 - 2026 by &lt;a href="https://www.linkedin.com/in/mathias-wolff-47a7941/">Mathias WOLFF&lt;/a> is licensed under &lt;a href="https://creativecommons.org/licenses/by-nc-sa/4.0/">CC BY-NC-SA 4.0&lt;/a>&lt;img src="https://mirrors.creativecommons.org/presskit/icons/cc.svg" style="max-width: 1em;max-height:1em;margin-left: .2em;">&lt;img src="https://mirrors.creativecommons.org/presskit/icons/by.svg" style="max-width: 1em;max-height:1em;margin-left: .2em;">&lt;img src="https://mirrors.creativecommons.org/presskit/icons/nc.svg" style="max-width: 1em;max-height:1em;margin-left: .2em;">&lt;img src="https://mirrors.creativecommons.org/presskit/icons/sa.svg" style="max-width: 1em;max-height:1em;margin-left: .2em;"></copyright><lastBuildDate>Sun, 03 May 2026 15:33:48 +0200</lastBuildDate><atom:link href="https://www.blog-des-telecoms.com/tags/sandbox/index.xml" rel="self" type="application/rss+xml"/><item><title>Securing pi, Your AI Coding Agent, with Greywall: A Practical Guide</title><link>https://www.blog-des-telecoms.com/blog/securing-pi-ai-coding-agent-greywall/</link><pubDate>Sun, 03 May 2026 10:00:00 +0200</pubDate><guid>https://www.blog-des-telecoms.com/blog/securing-pi-ai-coding-agent-greywall/</guid><description>&lt;p>&lt;strong>AI coding agents&lt;/strong> like &lt;strong>pi&lt;/strong> have become essential daily companions. But by default, &lt;strong>pi&lt;/strong> runs in &lt;strong>YOLO&lt;/strong> mode: full &lt;strong>filesystem&lt;/strong> access, unrestricted command execution, no permissions. It&amp;rsquo;s a deliberate design choice by its creator, but this freedom comes with real risks. Today, let&amp;rsquo;s explore &lt;strong>Greywall&lt;/strong>, a tool that &lt;strong>sandboxes&lt;/strong> pi using a &lt;strong>deny-by-default&lt;/strong> approach at the &lt;strong>kernel&lt;/strong> level.&lt;/p>
&lt;h2 id="why-sandbox-an-ai-coding-agent">Why Sandbox an AI Coding Agent?&lt;a href="#why-sandbox-an-ai-coding-agent" class="post-heading__anchor" aria-hidden="true">#&lt;/a>
&lt;/h2>
&lt;p>&lt;strong>pi&lt;/strong> in YOLO mode is convenient but risky. Without restrictions, the agent can:&lt;/p></description></item><item><title>Sécuriser pi, votre agent de code IA, avec Greywall : guide pratique</title><link>https://www.blog-des-telecoms.com/blog/securiser-pi-agent-code-ia-greywall/</link><pubDate>Sun, 03 May 2026 10:00:00 +0200</pubDate><guid>https://www.blog-des-telecoms.com/blog/securiser-pi-agent-code-ia-greywall/</guid><description>&lt;p>Les &lt;strong>agents de code IA&lt;/strong> comme &lt;strong>pi&lt;/strong> sont devenus des compagnons indispensables au quotidien. Mais par défaut, &lt;strong>pi&lt;/strong> fonctionne en mode &lt;strong>YOLO&lt;/strong> : accès complet au &lt;strong>filesystem&lt;/strong>, exécution de n&amp;rsquo;importe quelle commande, aucune restriction. C&amp;rsquo;est un choix délibéré de son créateur, mais cette liberté a un coût réel. Aujourd&amp;rsquo;hui, je vous propose de découvrir &lt;strong>Greywall&lt;/strong>, un outil qui permet de &lt;strong>sandboxer&lt;/strong> pi grâce à une approche &lt;strong>deny-by-default&lt;/strong> au niveau &lt;strong>kernel&lt;/strong>.&lt;/p></description></item></channel></rss>