Docker is advocating a secure-by-default approach for AI agents that execute code and call tools. The challenge extends beyond scanning an image: teams need provenance for models, dependencies and MCP servers, plus control over secrets and runtime actions.
The short answer
| Risk | Expected control |
|---|---|
| Compromised image | Provenance, signatures and continuous scanning. |
| Overpowered agent | Least privilege and explicitly allowed tools. |
| Untrusted code | Isolation, restricted network and disposable filesystems. |
| Invisible incident | Logs for tool calls, artifacts and sensitive decisions. |
A container is a useful boundary, but not when it receives the Docker socket, global secrets or unrestricted internal network access.
Agents expand the supply chain
A traditional application combines code and libraries. An agent adds prompts, remote models, dynamic tools and untrusted content read during a task. Any of these can influence the final action.
Inventory should therefore include images, SBOMs, extensions, MCP servers and approved models. Pin versions and review updates before they automatically reach privileged environments.
Isolate every task
Ephemeral execution reduces persistence of malicious files and makes cleanup straightforward. Mount only the required directory, preferably read-only except for a dedicated workspace. Deny network access by default and allow only required destinations.
Never pass a complete portfolio of secrets. Supply short-lived tokens restricted to one resource and easy to revoke. A permanent production credential can turn prompt injection into an infrastructure incident.
Put irreversible decisions behind approval
Publishing a package, merging code, deleting a resource or sending an external message should require approval or a deterministic policy. The agent can prepare the action and supporting evidence; the system retains the final decision.
Human approval only works when it presents a readable diff, intended commands and network destinations. A context-free “allow” button quickly becomes habitual.
Test outcomes, not just prompts
Evaluations should inspect created files, used permissions, external calls and the ability to stop. Deliberately place hostile instructions in an issue, document and dependency to test boundaries.
Agent security is an execution and supply-chain problem, not merely a model problem. Containers provide the necessary isolation when they remain ephemeral, narrowly permissioned and observable end to end.




Join the discussion
Comments
Loading comments…