BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The Sandbox is a Suggestion: Deconstructing AI Agent
  Sandboxes\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   
 When: Friday\, Aug 7\, 16:00 - 16:59 PDT\n   Where: LVCCW Level 1 Hall 3 1
 006 (Main Track 1) and DCTV-1 - [1]Map\n\n   Description:\n\n   Every majo
 r AI coding agent ships inside a containment system. I\n   analyzed three 
 of them - Anthropic's Claude Code\, Google's Gemini CLI\,\n   and OpenAI's
  Codex CLI - and each one breaks on its own terms.\n\n   Each sandbox uses
  a different containment model: permission-based\n   access control\, proc
 ess-level environment sanitization\, and\n   kernel-level filesystem enfor
 cement. Each makes a structural\n   assumption about what the runtime will
  do. Each assumption is wrong.\n\n   This talk deconstructs all three arch
 itectures\, shows what each claims\n   to enforce\, and demonstrates how t
 he containment fails - not through\n   prompt injection or model persuasio
 n\, but through gaps in the design\n   itself. Every exploit is determinis
 tic\, demo-ready\, and was reported\n   through coordinated disclosure.\n\
 n   Attendees leave with a reusable methodology for evaluating any AI\n   
 agent sandbox: identify the containment mechanism\, read the\n   enforceme
 nt code\, find the structural assumption it depends on\, and\n   test whet
 her the runtime violates it. The cross-vendor comparison\n   shows that di
 fferent engineering teams\, solving the same problem\n   independently\, m
 ake structurally similar mistakes - and that the\n   pattern is predictabl
 e once you know where to look.\n\n   SpeakerBio:  Elad Meged\, Novee Secur
 ity\n\n   Elad Meged is a Founding Engineer and Security Researcher at Nov
 ee\n   Security\, specializing in offensive security research and AI secur
 ity.\n   He holds an M.Sc. in Computer Science and has a background in\n  
  vulnerability research across web\, mobile\, and low-level systems\, with
 \n   experience in reverse engineering and platform internals. His current
 \n   work applies offensive research methodology to AI systems while\n   d
 eveloping AI-driven approaches to vulnerability discovery and exploit\n   
 verification.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T235900Z
DTSTART:20260807T230000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-
 1
SUMMARY:The Sandbox is a Suggestion: Deconstructing AI Agent Sandboxes
END:VEVENT
END:VCALENDAR
