Introducing The GitGuardian Mixin Kit To Extend Docker Sandboxes for Safer AI Coding

Modern enterprise security is increasingly being tasked with keeping agents from affecting critical data and infrastructure.
In this video, Dwayne, principal developer at GitGuardian, introduces how GitGuardian AI hooks extend the power of Docker Sandbox isolation. Their micoVM architecture plus the power of ggshield mean anyone can get an agent working in a secure way with very little effort.

Read the full post introducing Docker Sandboxes on the GitGuardian blog: https://blog.gitguardian.com/gitguardian-docker-sandbox-mixin-kit/

Get the GitGuardian ggshield-kit from DockerHub:
https://hub.docker.com/r/gitguardian/ggshield-kit

Or from the GitHub repository for the project:
https://github.com/GitGuardian/sbx-kit-ggshield

Learn more about Docker Sandboxes and get started with sbx today: https://docs.docker.com/ai/sandboxes/

Chapters:

0:00 Securing AI Agents and the Credential Layer

1:04 Isolating AI Agents with Docker Sandboxes

1:20 Extending Sandboxes with GitGuardian ggshield

1:45 Protecting the GitGuardian API Key with Docker Secret Store

2:02 How GitGuardian AI Hooks Stop Secret Exposure

2:37 Installing the GitGuardian Sandbox Kit

3:34 Verifying Sandbox Isolation

3:58 Verifying ggshield and AI Hooks

4:29 Test 1: Blocking a Secret in the User Prompt

4:59 Test 2: Blocking a Secret Retrieved from the Internet

5:35 Test 3: Blocking an Agent-Generated SSH Key

6:02 Docker Sandboxes + GitGuardian Credential Protection