1,000 Agent Tasks in a Sandbox: What Breaks When LLMs Write and Run Code
Kevin Orellana
- When
- Wednesday, July 12:25 PM – 2:45 PM · 20 min
- Where
- Track 1San Francisco, CA · imported from ai.engineer's public schedule feed
About this session
We ran 1,000 automated tasks through a production code interpreter sandbox — file I/O, package installs, data analysis, ML training, binary downloads, multi-language execution — and tracked every failure. 88% passed. The other 12% revealed 18 distinct failure modes that no unit test would catch: binary encoding corruption in the transport layer, null bytes silently truncating file downloads, pip blocked by network isolation with no useful error, and path traversal inputs accepted without validation. This talk walks through the experiment design, the findings ranked by severity, and what we changed. If you are building or operating sandboxed execution for AI agents, these are the bugs waiting for your customers to find first.
Speaker
Software Engineer, Amazon Web Services
Kevin Orellana is a software engineer at AWS, where he builds the sandboxed code-execution and browser-automation infrastructure that lets AI agents — including coding agents — run code and drive websites safely at scale. He previously worked on Amazon Bedrock's model-serving platform, where he tech-led the launch of Anthropic's Claude Sonnet on Bedrock and helped design the infrastructure behind several frontier-model launches.
More in Sandbox & Platform Engineering
- Don’t build agents, build environmentsWednesday, July 1 · 10:45 AM – 11:05 AM · Track 1
- Letting the Interns Loose — How We Accelerated AI Adoption.Wednesday, July 1 · 11:10 AM – 11:30 AM · Track 1
- Kubernetes Is Not Your SandboxWednesday, July 1 · 11:40 AM – 12:00 PM · Track 1
- Your agent needs a sandbox, not a desertWednesday, July 1 · 12:05 PM – 12:25 PM · Track 1
- From fork() to Fleet: Designing an Agent Sandbox Cloud Pt 1Wednesday, July 1 · 1:30 PM – 1:50 PM · Track 1
For developers: this programme is open data — JSON, iCal, schedule XML and an MCP endpoint.Show endpointsHide
- JSONEvery published session and speaker, in one request./aie-worldsfair-2026-import/feed.json
- iCalSubscribe in Google, Apple or Outlook Calendar./aie-worldsfair-2026-import/feed.ics
- Schedule XMLfrab / pentabarf — the format conference apps import./aie-worldsfair-2026-import/feed.xml
- MCP + RESTPoint Claude at the programme. OpenAPI 3.1 included./agents
No key, no signup, CORS open. Everything here is generated from the same data the organisers edit.