28Your agent writes and runs code against user data. Design the sandbox.▼hardOpenAIAnthropicRetool1 replies◆ premiumThe model is an untrusted code author with an unlimited imagination, and prompt injection means it can be *aimed*. Strong answers pick an isolation primitive deliberately, then close the channel most designs leave wide open: the data the code is allowed to touch.Open full answer →
45A customer wants a computer-use agent operating inside their CRM and ticketing apps. How do you deploy it safely?▼hardNewAnthropicOpenAI◆ premiumCandidates treat computer-use agents like API agents with a screenshot. The interviewer is probing the new visual attack surface (hidden text, off-viewport UI, injected images) and how containment changes when the agent drives a real customer desktop. Most miss the per-turn-approval trap.Open full answer →