Argument · Wrench 0.16.1
A VM is not an attested web operation.
The Wednesday 26 August 2026 rough.day tech edition ranked “Trail of Bits argues VMs cannot reliably contain cyber-capable AI agents” as item four. The live source is Artem Dinaburg’s 26 August 2026 post VMs won’t contain cyber-capable agents. Wrench does not treat that isolation story as its job. It names a provider operation, attests whether the current contract can run it, and refuses to pretend a missing operation was proven.
This argument uses the live Trail of Bits post fetched for this draft, the Wednesday 26 August 2026 rough.day tech edition, the rough.day selection notes, and the public v0.16.1 pages for the Wrench home, provider capability attestation, security guide, inbound index-spoofing argument, and personal-agents comparison. Operation counts are the current release attestation, substituted at site build time.
Wednesday ranked a containment claim, not a Wrench contract
rough.day considers reporting from the previous 24 hours, groups related coverage, and publishes up to six stories per category when the day supports that many. Its selection notes say the tech edition favors demonstrated impact and durable change over product promotion. The Wednesday 26 August 2026 tech list placed the Trail of Bits argument at rank four, with blog.trailofbits.com as the source host.
The ranked title is the edition’s headline. The live post title is “VMs won’t contain cyber-capable agents,” published 26 August 2026 by Artem Dinaburg. This page names both. It does not reprint the edition summary or the post’s exploit tables.
Hraness publishes Wrench and this site. The edition is an independent ranking of a public security argument. It is not a Wrench release note, and a ranked story does not add a provider operation.
A guest machine still shares a hypervisor, side channels, and egress
Dinaburg writes that a useful agent VM has to share resources with the host and almost always needs some network access. Those shared pathways are the problem. In the post, GPT 5.6-Cyber escaped a QEMU/KVM guest on a Debian 12 host three times: first through a recently disclosed host-kernel bug, then through a guest-networking library that still shipped a known hole on oldstable, then through a chain that included 0-days in QEMU and KVM.
The post’s plain statement is that you can no longer assume a mere VM will contain a sufficiently advanced AI agent. An off-the-shelf VM leaves too much attack surface. Even a display adds surface. A later Firecracker run hardlocked the machine from remaining kernel flaws and did not complete an escape in the time available. The post treats that as a harder target, not a closed box.
Hypervisor bugs, unmarked library holes, host services reachable through guest networking, and side-channel attempts all sat inside that one experiment. Egress was not an extra concern after isolation. It was one of the escape paths. Wrench does not claim to close those paths. It does not sell a hypervisor, a microVM, or a hostile-code sandbox.
Attestation names the operation before anything leaves
Wrench’s job is the opposite of a general sandbox. A sandbox tries to let an agent roam, then hopes the box holds. Wrench starts with the named outcome an agent may request. The Wrench home states that each authenticated operation is typed, bounded, and tied to one account and transport. The caller brings the model and interface. Wrench supplies the local capability and custody layer. It is not an AI agent, planner, or approval shell.
The security guide makes the bind exact. An authenticated operation binds one named outcome to an exact provider, transport, account realm, contract version, implementation, input, and risk. Credentials stay opaque to the caller. When those facts drift, the operation stops instead of changing transports or falling back to general browser control.
The current release attests 322 operations across 22 bundled public adapters. 135 are observed. 187 remain capture-required. Those figures are the same release-bound counts published on the provider capability attestation. This page does not add a provider, invent an extra operation, or treat a reservation as ready. Telegram is absent from those manifests. Wrench does not install a Telegram Bot API substitute or claim Telegram contact access.
observed means the current contract can plan and execute after local doctor and auth checks pass. capture-required is an inert reservation. The attestation page says a missing or capture-required operation stays unavailable rather than falling back to general browser control. Absence of a reviewed contract is not treated as a passing containment test.
Containment, identity, and browser recovery answer different questions
The index-spoofing argument asks whether a claimed inbound bot name can stand in for an outbound contract. The personal-agents comparison asks whether a persistent browser loop can stand in for that same contract. This page asks whether a VM around the agent can stand in for attestation. The pages refuse different substitutes.
| Decision | Off-the-shelf agent VM | Wrench attested operation |
|---|---|---|
| What is named | A guest machine that should contain the agent | A named outbound outcome such as messaging.list |
| What remains shared | Hypervisor, host kernel, guest networking, and often a display | Exact provider, transport, account realm, contract version, implementation, input, and risk |
| Failed check | The guest can still reach the host. The post records three escapes | The operation stops. A capture-required reservation stays inert |
| Missing proof | A harder hypervisor is still not a completed containment proof | The reservation cannot plan or execute, and Wrench does not invent a browser fallback |
| Job of the layer | Let the agent roam inside a box | Name the operation and attest whether it is available |
A Firecracker run, successful or not, still does not name messaging.list or mark a reservation observed. The post is evidence that isolation remains leaky. It is not a Wrench capability grant.
Read the spoofing page for inbound identity. Read the comparison for browser-using personal agents. Read this page for why a guest machine is not an attested operation. None of the three reprints the others.