Docker is bringing its Sandbox Kit Specification to the Cloud Native Computing Foundation, proposing a portable way to package an AI agent together with its tools and requested permissions. Version 3 uses an ordinary Open Container Initiative image rather than a custom artifact, so existing registries can pull, sign and scan it.

A descriptor inside the image lists typed capabilities such as network policy, credentials and mounted volumes. Permissions are requests rather than automatic grants: the host runtime decides whether to allow them and must refuse launch when a required capability cannot be provided. Deny rules take precedence, and a credential proxy can keep the real token outside the sandbox.

Pinning an image digest binds code and permission declarations to the same version. Runtimes can compare normalized grants and block an update that silently widens access or removes a restriction. Multiple “mixin” images can add capabilities, with dependency resolution rejecting incompatible or missing requirements. Docker Sandboxes, which isolates agents in micro virtual machines, is the first conforming runtime.

The Apache 2.0 specification includes conformance tests for both artifacts and runtimes. Docker says it developed examples with several infrastructure and security companies. The proposal has been announced for CNCF involvement, but the source does not say that CNCF has accepted it into a project program or assigned a maturity level.