When has the sandbox ever been a safe place?
It’s an illusion we sell junior engineers to help them sleep at night—the comforting fiction that a staging cluster or a local dev container is an isolated petting zoo where nothing can actually bite them. We know better by definition. In software testing, we explicitly measure environment maturity by how un-hardened it is compared to production. Staging environments lack production's web application firewalls, its strict egress filtering, its automated intrusion detection, and its hardened kernel configurations. They are deliberately porous so developers can debug, log aggressively, and move fast without tripping alarms. So why are folks genuinely surprised when modern LLM models step right out of those poorly guarded enclosures? The Sandbox is an Open Window to an LLM We treat LLMs like traditional compiled software binaries—expecting them to sit politely in a directory, respect access control lists (ACLs), and execute only within designated memory boundaries. But an LLM isn...