AI LABS
Containment Wing · VM agios-kernel
HOT WORK HAPPENS BEHIND THIS GLASS
SEALED
linux 6.9 DISPOSABLE KERNEL · REBUILT ON DEMAND if an experiment ruins it, the lab prints a new one INJECTION PROBE CONTAINED AT THE FENCE containment tests · F.1 cmd injection ...... BLOCKED shell escape ....... BLOCKED net egress ......... NONE host filesystem .... UNREACHABLE 8/8 checks · 3/3 flake-stable the agent's code runs in there — the agent itself never does · one-way specimen hatch · verdicts out, nothing in
Why a cage
Agent-written kernel code is hot material. It gets full freedom inside the cage and zero outside it. That trade is what lets the lab run without a human safety officer per experiment.
Spec
Lima VM · isolated netns
fresh state per benchmark
90s hard cap per verify
spec in infra/ · reproducible
Containment Log
last probe: adversarial payload in program_name field → neutralized at tool boundary → logged → FAILURE_LESSON not needed (the fence is not a lesson, it is a wall)