Spens launches agent sandboxing with full execution observability Spens, a Show HN project, launched agent sandboxing that runs coding agents in isolated Docker containers and logs every network call, tool invocation, and file change for review in a local web viewer. The tool requires Python 3.11+ and Docker, runs agents as unprivileged users blocked from system files and home directories, and intercepts all LLM API calls and HTTP requests while injecting API keys only to approved domains. Spens launches agent sandboxing with full execution observability Spens, a Show HN project, runs coding agents in isolated Docker containers and logs every network call, tool invocation, and file change for review in a local web viewer. The tool requires Python 3.11+ and Docker, runs agents as unprivileged users blocked from system files and home directories, and intercepts all LLM API calls and HTTP requests while injecting API keys only to approved domains. Topics Sources - Official Read article https://spens.refwd.ai/ Go deeper This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.