Skip to content
Use case 099

AI Coding Agent Sandboxes

A deployment concept for Coding-agent vendors purchasing or building hosted execution infrastructure; Enterprise developer-platform teams procuring isolated agent workspaces; Software delivery integrators embedding coding agents into existing development platforms.

Deployment concept · Suitability unverified
Artificial Intelligence and Data Systems

Why this environment matters

A coding agent may legitimately run package managers, compilers and tests that execute repository-controlled code. Giving it an entire developer workstation turns that ordinary task into access to unrelated projects, credentials and release systems. This concept defines an execution boundary around one reviewed development task.

The security challenge

A task could begin with a specific checkout, a writable work directory and an explicit list of permitted commands or tool classes. Build scripts would run inside that scope even if they were pulled from the repository itself. The agent would not receive a developer’s general home directory or ambient cloud credentials as a convenience.

How the capsule model could help

NØNOS capsules could separate the agent controller from build execution and artifact export. Dependency retrieval would use a narrowly scoped network path. Release signing and production deployment would remain outside the agent’s permissions, with an independently reviewed artifact crossing the boundary only after the development task completes. A compromised repository can make an apparently helpful build step read secrets, alter another checkout or substitute the file eventually exported. The prototype would therefore bind the returned patch and test artifacts to the workspace that was actually evaluated. It would record relevant tool results without allowing a generated success message to stand in for execution evidence. Compatibility is a substantial constraint. Existing compilers, language runtimes and build tools cannot simply be assumed to run inside NØNOS. An early evaluation should choose a supported, limited toolchain and demonstrate the boundary before attempting a broad developer environment.

Separate address spaces and capability checks can limit cross-process reach. They cannot stop harmful use of legitimate permissions, prove AI decisions correct or substitute for domain-specific safety controls.

Deployment requirements

The design does not prove generated code correct or make arbitrary build tools compatible with NØNOS. Human review, dependency governance and separate release credentials remain necessary parts of the development workflow. Evaluation requirements: Use a test repository whose build script attempts to read a sentinel secret outside the workspace; access should fail. Request dependency retrieval from an unapproved destination and verify the configured refusal or review path. Modify an artifact after testing and confirm that export identifies the change rather than presenting the earlier test result as current.

Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.

A repository is work input and executable material

A task could begin with a specific checkout, a writable work directory and an explicit list of permitted commands or tool classes. Build scripts would run inside that scope even if they were pulled from the repository itself. The agent would not receive a developer’s general home directory or ambient cloud credentials as a convenience.

NØNOS capsules could separate the agent controller from build execution and artifact export. Dependency retrieval would use a narrowly scoped network path. Release signing and production deployment would remain outside the agent’s permissions, with an independently reviewed artifact crossing the boundary only after the development task completes.

A patch is an output, not approval to ship

A compromised repository can make an apparently helpful build step read secrets, alter another checkout or substitute the file eventually exported. The prototype would therefore bind the returned patch and test artifacts to the workspace that was actually evaluated. It would record relevant tool results without allowing a generated success message to stand in for execution evidence.

Compatibility is a substantial constraint. Existing compilers, language runtimes and build tools cannot simply be assumed to run inside NØNOS. An early evaluation should choose a supported, limited toolchain and demonstrate the boundary before attempting a broad developer environment.

Who could buy or integrate it?

  • Coding-agent vendors purchasing or building hosted execution infrastructure
  • Enterprise developer-platform teams procuring isolated agent workspaces
  • Software delivery integrators embedding coding agents into existing development platforms

Industry examples: GitHub, Anthropic. These are research prospects, not represented as NONOS customers, partners or endorsers.

Opportunity research

Separate the market from the model.

Published industry benchmark
US$7.6 billion

AI agents

Global · 2025 · annual market estimate

Agent products across business and consumer applications; includes ready-made and custom systems beyond execution sandboxes.

Modelled global devices
50K–5M

Candidate OS endpoints

Hypothetical planning range · 2025

Low, hypothetical planning assumptions. Hardware eligibility, procurement and adoption remain unverified.

Illustrative annual licensing
$4M–$1.5B

USD / year at full model coverage

Device scenario × assumed US$80–$300 per device / year.

Not a revenue forecast, announced price or measured serviceable market.

Device calculation

Hypothetical global planning range, 2025 scenario: assume 10,000–100,000 engineering organizations hosting coding-agent execution infrastructure × 5–50 candidate OS endpoints per site/asset = 50,000–5,000,000 endpoints. Counting unit: durable sandbox worker hosts; ephemeral sandboxes on a host counted once. Site/asset counts and endpoint densities are author assumptions, not a measured installed base. Coverage is limited to the defined equipped subset; includes all candidate endpoints within that assumed subset. Hardware eligibility, certification, adoption and achievable NØNOS share are unverified; overlaps other cases.

AI agents market report ↗

Context only, inherited market research; not a device/site denominator. Original monetary-market scope and geography are preserved in benchmark. This source does not establish the assumed worldwide site count or endpoint density.

How to interpret the figures

Adjacent or broader commercial market benchmark; not the NØNOS OS market, licensable-device count or revenue forecast.

Modelled candidate endpoints × assumed annual USD per-endpoint price. Price is an author assumption, not a vendor quote. Full-range mathematical scenario only: not a revenue forecast or TAM; excludes adoption timing, procurement, certification, support costs, channel economics and attainable market share. Case totals overlap and must not be added.

Inherited research compiled 13 Sep 2026; publisher estimates, not independently audited.

Read the full methodology

Explore NONOS

Choose your
NONOS experience.

Discover the platform for your organisation or explore the software.

You can reopen this chooser from the footer at any time.