This blog post discusses the security challenges faced by AI coding agents, especially concerning the execution of untrusted code in shared environments. It compares two technologies, NVIDIA OpenShell and Red Hat OpenShift sandboxed containers, each addressing different aspects of security vulnerabilities. The article emphasizes the need for a layered security architecture by showcasing how using OpenShell within OpenShift can help cover blind spots in safeguarding against both application-layer and kernel exploits.