AI Tinkerers Sandbox Symposium · March 7, 2026

Sandbox Inception

Using AI agents to test "agent-native" sandbox platforms. The process of testing revealed more about agent-readiness than any feature matrix could.

36
Security attacks
2
Live sandboxes
3
Platforms tested
14
Learnings
Journey page

The Journey

The full story of our agent-first testing approach โ€” from the inception idea through the OAuth wall, SDK bugs, security deep-dive, and final scores.

Full Writeup
Dashboard

Live Dashboard

Real benchmark data, platform scores, security matrix, inception architecture visualization, and the hurdles log โ€” all from live testing.

Interactive

Key Findings

๐Ÿ”’

The Auth Wall

Every "agent-native" platform requires browser OAuth signup. No agent can start without human help.

โšก

Root Access in MicroVMs

Blaxel runs as ROOT with full capabilities. /etc/shadow readable, /etc/passwd writable. Daytona has passwordless sudo.

๐Ÿงช

The iTool Pattern Works

Provision sandbox + install Claude Code + delegate + teardown = ~2 seconds total. Viable for production.

Daytona

4.0
/ 5.0

Ona

3.5
/ 5.0

Blaxel

3.1
/ 5.0

Team

Fadi

Human orchestrator & project lead

Kai

AI agent (OpenClaw) โ€” benchmarks & security attacks

Claude

Cowork mode โ€” research, analysis & deliverables