This was generated by AI during triage.
Goal
Prevent and independently detect container-escape precursors and containment violations for agent workloads.
Scope
- Require MicroVM isolation for designated high-risk workload classes and fail closed when unavailable.
- Add external runtime-observation adapters for namespace, mount, privilege, container-runtime socket, firewall, device, and unexpected listener activity.
- Persist containment events as Artifacts and add deterministic containment-integrity block gates.
- Ensure in-container telemetry is never the sole source of a safety verdict.
Acceptance criteria
- High-risk execution cannot silently fall back from MicroVM to a plain container.
- Verified violations halt the run and preserve forensic evidence.
- Synthetic tests cover both detected violations and normal allowed operation.
Goal
Prevent and independently detect container-escape precursors and containment violations for agent workloads.
Scope
Acceptance criteria