Modern self-hosted agents use Docker containers, Apple containers, gVisor, or Workers runtimes as sandboxes. The sandbox enforces filesystem boundaries, network egress allowlists and resource limits. Sandbox-on-by-default is the post-OpenClaw-crisis baseline expectation.
Related terms
Found a definition that's wrong, dated or could be sharper? Email us — we update with attribution unless you'd rather we didn't.