Seccomp

1essay ·All tags

Agent Safety22 min read

Syscall Allowlisting: The Strict Diet for Agents

Blocking binaries is not enough. Seccomp allowlists shrink the system vocabulary so common exploits fail closed — Tetragon decides which programs may start; seccomp decides which syscalls those programs may still speak.

  • Seccomp
  • Sandbox
  • Agents
  • Security
  • Docker