Practical Security Guidance for Sandboxing Agentic Workflows and Managing Execution Risk | NVIDIA Technical Blog
…Use virtualization to isolate the sandbox kernel from the host kernel (e.g., microVM, Kata container, full VM) Require user approval for every instance of specific actions (e.g., a network connection…