Docker is advocating a secure-by-default approach for AI agents that execute code and call tools. The challenge extends beyond scanning an image: teams need provenance for models, dependencies and MCP servers, plus control over secrets and runtime actions.

The short answer

RiskExpected control
Compromised imageProvenance, signatures and continuous scanning.
Overpowered agentLeast privilege and explicitly allowed tools.
Untrusted codeIsolation, restricted network and disposable filesystems.
Invisible incidentLogs for tool calls, artifacts and sensitive decisions.

A container is a useful boundary, but not when it receives the Docker socket, global secrets or unrestricted internal network access.

Agents expand the supply chain

A traditional application combines code and libraries. An agent adds prompts, remote models, dynamic tools and untrusted content read during a task. Any of these can influence the final action.

Inventory should therefore include images, SBOMs, extensions, MCP servers and approved models. Pin versions and review updates before they automatically reach privileged environments.

Isolate every task

Ephemeral execution reduces persistence of malicious files and makes cleanup straightforward. Mount only the required directory, preferably read-only except for a dedicated workspace. Deny network access by default and allow only required destinations.

Never pass a complete portfolio of secrets. Supply short-lived tokens restricted to one resource and easy to revoke. A permanent production credential can turn prompt injection into an infrastructure incident.

Put irreversible decisions behind approval

Publishing a package, merging code, deleting a resource or sending an external message should require approval or a deterministic policy. The agent can prepare the action and supporting evidence; the system retains the final decision.

Human approval only works when it presents a readable diff, intended commands and network destinations. A context-free “allow” button quickly becomes habitual.

Test outcomes, not just prompts

Evaluations should inspect created files, used permissions, external calls and the ability to stop. Deliberately place hostile instructions in an issue, document and dependency to test boundaries.

Agent security is an execution and supply-chain problem, not merely a model problem. Containers provide the necessary isolation when they remain ephemeral, narrowly permissioned and observable end to end.