Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.
Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.

AI Engineer · @aiDotEngineer
This video has no Most replayed graph yet: YouTube shows one only once a video has enough views. These are the moments viewers replayed most in AI Engineer's most watched videos.
Most replayed moment at 11:58
4.6x that video's typical replay level
issues. Uh I also invented OS certification. I just close the tracker whenever I want, so I have my life back. So, does this work? Yes, sort of. >> [laughter] >> Which leads me to act three, slow the down. Everything's broken.
Said at 11:52
Most replayed moment at 18:45
4.8x that video's typical replay level
that they're they're changing they're changing things in the database not yet. You want to run them through the ontology first and make sure that works. Okay. I only got an I've got I've got another I've just a short time. I'm going to try to show you some of the things that um that you can
Said at 18:37
Most replayed moment at 16:13
3.6x that video's typical replay level
method signatures, the program layout and the call stacks. So here's some examples. I don't think you'll be able to read this one, but this is like the level of abstraction we're at. It's how we're actually going to lay this stuff out and how these systems are going to interact. Dylan Mulroy from Cloudflare talks a
Said at 16:06
The graph counts replays. It does not show where viewers stopped watching.
Words
2,055
Runtime
11:35
Speaking pace
177wpm
Reading time
9min
177 words per minute, between the 160 25th percentile and the 181 median of 349 measured videos. That distribution comes from the 349-video hook study.
Opening (first 30 seconds)
Hey everybody, I hope you had a good lunch. I know it's one of the last talks of the entire conference. I tried to make it somewhat engaging and amusing. So, you know, audience participation is is encouraged. We'll see how it goes. So, I'm here with Docker. Uh, I'm one of our product managers that works on our new sandbox product. I don't know if you've seen it. It's a new binary for Docker. It's called SBX. Uh, it's a microVM. It's really cool. You should come check
89 words, the words spoken in the first 30 seconds at 177 words per minute.
Free, no signup. See how the first 30 seconds hold attention, with rewrites.
Sentence shape
| Measure | This transcript |
|---|---|
| Sentences | 151 |
| Average words per sentence | 13.6 |
| Longest sentence | 47 words |
| Questions asked | 11 |
| Sentences containing a number | 4 |
Most used terms
Filler phrases
85 in total: uh 35 · like 14 · you know 11 · actually 7 · right? 6 · um 6 · kind of 5 · sort of 1.
A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.
Free, no account. See where attention is likely to drop, with a rewrite for each weak line. The free check shows the scores and the one issue costing the most. Or run it on the words above first.
Free · No login · See a sample audit first if you prefer.
What this transcript is
Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.
Hey everybody, I hope you had a good lunch. I know it's one of the last talks of the entire conference. I tried to make it somewhat engaging and amusing. So, you know, audience participation is is encouraged. We'll see how it goes. So, I'm here with Docker. Uh, I'm one of our product managers that works on our new sandbox product. I don't know if you've seen it. It's a new binary for Docker. It's called SBX. Uh, it's a microVM.
It's really cool. You should come check it out. But I'm going to tell you why uh you might want to use it in context of agents doing governance and being safe in general for your agentic platforming needs. So right now, you know, all of you are doing way more AI than you ever thought you would 5 years ago. At least I am. And we generally think that we're being protected by our coding harnesses because if we try to do something bad, they will sometimes stop us.
And when we see stories, we think, "Oh my gosh, I would never make this mistake to have my AI drop my prod database. You know, I've been doing coding for 30 years. There's no way I would possibly do that." So what I decided to find out was well what happens if I actually try to hack myself and how far can I get with you know our tools and what we've been told is a safe environment. So I opened up my claude code on desktop on my Mac and I had it look for my browser history uh and it found it right away which I was very impressed about.
And I asked it uh what can I what can I do with this? And so we started looking at my bank accounts which I was uh surprised about. And it found them. Uh which I was very unhappy about. I made fake bank names. This is not my real data, just so you know. But it did find all of my real bank data on there. Uh and it went even further. It found that I've been ordering checks recently, that I've been using zel. It told me the last four digits of the account I was using.
Um I was I was very impressed. And here's kind of an idea of all the PII that it found. Um, this is from again the clawed desktop app uh that we thought was safe. Anyways, maybe maybe there's a better solution. Who knows? So, the next day I came in and I got from my security team uh a nice little notice that I they thought I'd been hacked. And so I had to explain to them that no, no, no, I'm just putting together a talk for this conference and uh please please don't flag me as a as a a compromised computer.
And then they sent me the crowd strike report from this which I asked them to do. And I was quite impressed with it. Apparently this is a known way to get uh credentials from a machine. Didn't realize that. And I had scored very well on this. I got a nine out of 10 which uh is better than I did in most of my classes. So that was that was really good. But fortunately this was just me internally. It was not some sort of you know injection from a script or MCP server or anything that could easily happen.
So five five prompts is what it took. Um I had to be a little clever. I couldn't if I just if you just ask straight up like hey Claude go find my bank data. It kind of it it will give you a warning. But if you say, "I'm researching how to do security," it'll happily go and help you do that research on your account. It is not uh it's not your friend. So if if only there was a better way to do this using a sandbox microVM technology that Docker and others have released recently.
So rather than just saying please which you know if you look in some of these cloud prompts you'll see please don't do nefarious things right like that is the level of security we're at. So now we've got microVMs if you're not aware of them compared to I know you're probably all aware of Docker been using it for years. The new thing now that we and others are doing is with microVMs they run their own kernel. They isolate your file system.
We have a system that will go and make sure that the sandbox never actually sees your secrets. When you try to go and do a network request, it takes a placeholder, replaces it so that your sandbox and your agent can't do bad things. We've got a full audit trail for it. Uh so yeah, we want to be you want to be secure by design, not just, you know, hope and say please and see what's going to happen. We're trying to do this balancing act, right?
If we don't actually if we can't actually do these things, the agent's not useful. So that's why this whole sandbox idea is so exciting for us. We encourage you to use it. Um, and maybe, you know, don't let your bank data get into the hands of your agent. That's not that's not what you want. So this is what it looks like in practice when you're running a sandbox. Uh on the uh left side is when I run claude and on the right side is when I do sbx run claude.
And you can see that there there's a lot of uh differences. That's a joke. Sorry, they're not. It's just the bypass permissions are on, but it's nothing nothing else uh was hard to do. Right. Running that command on the right automatically creates a new VM. It spins it up in that folder and it makes a new sandbox for you. It runs your agent. Now you're up and running. It can't see anything. So if we try to do our browser history attack on regular claude, it happily goes and finds your browser history.
But if I run it on the sandbox version, it does not even think there's a browser installed on your machine. So pretty cool. No difference. I had to type uh seven more keystrokes to get here, but I think it's well worth the uh the price to pay. Same thing is true for network egress and ingress. So, right here, I'd uh I tried to get it to go and look up uh the pirate bay because I I knew that would be blocked and sure enough, blocked by default.
The other thing you kind of see, it's hard, maybe it's hard to see, but like the uh Claude likes to really send back a lot of telemetry data to their data dog instance. So if you're using Claude, uh you are sending anthropic a lot of your data, unless you're using sandboxes, in which case you're cleverly being blocked by that. The other thing I'll say about sandboxes, they're so easy to use. Every developer at Docker now writes all of their code in sandboxes.
So we are using this every day. Hey, we're writing all of our code in it. If we don't use it, we get uh we get yelled at. So, it's worth our time to to go and do that little defaults on this. All of this is configurable. Um, and so now that we talked about like why this matters, right? So, doing this at the harness level doesn't really work. Agents find their way around it. If it gets down to your host machine, it's too late.
So, you want to be at that microVM boundary. We think it's the best way. other people do too. And it's easy to use. If you're working in consulting, if you've got a, you know, chief security officer, if you do client work, whatever it might be, you're probably dealing this with this on a day-to-day basis. So, not only do you want this to be useful, but also you want to do things and enable your agents to do different things, right?
So, one of the things we're really excited about is doing like agent level identity tracking and delegation chains. So, when you can start saying, "Hey, how come this thing happened?" And you can go back and say, "Oh, that's because an agent did it and a human actually authorized that agent to do it. It didn't just happen by magic. We didn't know. We don't it's not like we don't know how what happened." Now, we're going to start tracing that, tell you tell you about it, and let you write policy that actually goes and does degradation of uh what you can do based on Cedar policies based on new new things happening.
And you might say to yourself, "Oh my gosh, this is so good. I would like I would like to buy it now. How do I how do I buy this from you guys?" And so I have my marketing slide that my marketing team is really mad at me that I made this, but I think it's funny and cute for AI governance. So definitely talk about that. Okay. What does AI governance look like? You're doing this is what this is what it looks like in kind of a mockup.
So right now we've do we do network, you can set allow, deny, you can do file system uh points, and you can also decide what your MCP catalog looks like. Also, if you're running our MCP server, our MCP servers themselves run on a sandbox. So, they are also governed by all of these different controls. In the future, we're going to be adding more stuff. One of the things we've heard from a lot of people at this conference is that they want to do uh L7 networking controls.
They want to do uh like per GitHub repo file system level controls, right? like you want your agent to be able to read and write to some repos and some areas of some repos but not others, right? So, all of this is going to be coming down the line, but everything that I've showed you today is working. Um, and you should come by our booth and see that it's easy to install. We run on Mac, Windows, and Linux uh based on your uh package manager of choice.
And you can see at the end it's just sbx run. It's not just cloud by the way. The the sandboxes are a full VM. So you can run a shell, you can run codeex, you can run whatever, you can run a python job, you can run a web server, anything you want to do, but we want to make it easy for you to get in and up and running. So this is kind of our default. So you can just get in, you can get that cloud code or codeex instance going.
It feels native. It works just the same way as your one did today, but you've got all these protections in store. Uh, additionally, you can mount other file systems. So, what I do is when I'm working on a, you know, a piece of code with related repositories, I'll mount those uh, read only. That way, my agent can see what I'm doing, it can see my other codebase, but I know it's not going to make random commits to other repos just to make my thing work, right?
I want the guarantee that it's actually doing what it says it's doing with the API that I've specified. So that's it. Pretty short. We have a booth. We have a few sunglasses left and some power banks to give away. You should come by our booth and I'll walk over there afterwards and give you the demo and then you can look as good as uh Macho Man Randy Savage with those glasses. So there you go. Thank you.
The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.
Free tools for your own script: paste a draft and see where it stands before you record it.
Paste your draft and see where viewers are likely to drop off, with a rewrite for each weak line.
Paste the first 30 seconds of your own draft for a hook score and rewrites.
Check your draft against YouTube's advertiser-friendly guidelines before you record it.
Read this channel's public videos and transcripts, and download a writing brief for it.