Listen to the full episode.
The sandbox was only as isolated as the services it was allowed to trust.
The episode examines how a package proxy and shared infrastructure can become a lateral path from a high-capability evaluation workload into systems it was never intended to reach.
It then compares two control models: stronger physical or hypervisor isolation for crown-jewel evaluations, and tightly monitored Zero Trust environments for routine workloads.
The decision at the centre of the episode
Contain the trust path first. Isolate shared infrastructure, preserve external telemetry, rotate affected credentials and resume only from known-good immutable dependencies.
Read the technical analysis
The companion analysis sets out the evidence, technical implications and verification work in a concise written reference.
Related analysisWhen AI Crossed the Trust BoundaryRead analysis →
