When AI Agents Get Shell Access: Securing Agentic Workloads on Linux

AI agents are evolving from conversational assistants into systems that can execute shell commands, modify files, call APIs, start containers, and interact with production infrastructure. Giving an agent these capabilities can unlock powerful automation—but it can also turn a bad model decision, prompt-injection attack, or compromised tool response into a serious security incident.

This session explores how Linux security primitives can be used to contain agentic workloads before they are trusted with real systems.

We will build a practical threat model for an AI agent with access to the operating system and examine risks such as excessive privileges, unsafe command execution, credential exposure, unrestricted network access, resource exhaustion, and accidental modification of host files.

The session will then demonstrate how to reduce these risks using rootless containers, Linux namespaces, cgroups, capability dropping, seccomp profiles, read-only filesystems, AppArmor or SELinux policies, network restrictions, ephemeral credentials, and detailed audit logging.

A live demonstration will compare the same agent running in an overly permissive environment and in a hardened Linux sandbox. We will observe which dangerous operations succeed, which are blocked, and how the security controls affect the agent’s behavior.

Attendees will leave with a practical architecture and security checklist for running AI agents that can safely interact with Linux systems, containers, APIs, and infrastructure.

Pragya Keshap

Pragya Keshap is a Technical Architect with more than 18 years of experience designing enterprise, cloud-native, and AI-enabled systems. She is a Google Developer Expert in Google Cloud and a Docker Captain.

Her work focuses on distributed systems, containers, Kubernetes, cloud security, API platforms, generative AI, and reliable agentic architectures. She has designed and led large-scale technology initiatives in the financial-services industry and regularly writes and speaks about building secure, observable, and production-ready AI and cloud-native systems.

Pragya’s technical articles have appeared in publications including InfoQ, O’Reilly Radar, DZone, Cloud Native Now, and HackerNoon. She has also presented at developer communities and technology conferences on Docker, Google Cloud, AI agents, confidential computing, and cloud-native architecture.

Akhilesh Keshap

I am a software engineer by education, but a problem solver by attitude. In my 12 years of experience spanning across various industries such as E-commerce, Cloud, SaaS Technology, Payments, Investment banking and Fintech, I have worked and managed large-scale, complex and multi-geographic projects in Technology and built products that customers love. During this time, I have worn multiple hats such as Product Manager, Go to Market strategy and execution, Team leader, Coach, etc.