Docker has announced it is contributing the Sandbox Kit Specification to the Cloud Native Computing Foundation, a move designed to make the permissions an AI agent requests as transportable as the agent software itself. The company revealed the donation at the WeAreDevelopers conference on September 24, offering the Apache 2.0 specification, now at version 3, which bundles an agent, its tools, and a typed catalog of the hosts, credentials, and storage volumes it needs into a standard OCI image. The spec aims to solve what Docker describes as a fragmentation problem: AI agents like Claude Code and Codex install software, call APIs, and use credentials on behalf of users, but the grants that enable them—such as bind mounts, broad tokens, and firewall exceptions—typically exist in shell history, dashboards, and memory rather than in a reviewable package.

In the third version of the specification, a Kit is no longer treated as its own distinct artifact type; it carries no custom media type and no sidecar file, with the manifest containing one declaration: vnd.docker.sandbox.kit.descriptor. This design means a Kit can be built with docker buildx build, pulled with docker pull, and scanned, signed, or referenced in a FROM statement, with digest pinning locking both content and permissions together. Declarations are typed and versioned capabilities, such as com.docker.sandbox/network-policy@2 and com.docker.sandbox/credential@1. In the spec's GitHub CLI example, the Kit permits api.github.com but blocks DELETE on /repos/**, since deny rules take precedence. Credentials can be proxy-managed: a conforming runtime injects the actual token into requests to specified domains, while only a placeholder value exists inside the sandbox.

According to the report, a Kit only requests permissions; the host makes the final decision. Without a conforming runtime, the annotation remains inactive, and if a required request can't be met, the launch is refused. Docker Sandboxes, which run agents in microVMs with their own kernel, is the first conforming runtime. A launch combines one workload Kit, which supplies the root filesystem, with any number of mixin overlays. CNCF CTO Chris Aniszczyk welcomed the contribution, stating: "Standards are what let an ecosystem move fast without fragmenting, and few companies understand that better than Docker." The company says it has built Kits with AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, and Snyk, among others, and that two conformance suites ship with the spec—one for Kit artifacts and one for runtimes.

Docker draws a parallel to its earlier donation of the image format and runc that led to the creation of OCI, arguing that the current spec addresses the same kind of fragmentation OCI was designed to prevent, where every runtime vendor could otherwise invent its own solution. The report notes that while existing registries, scanners, and signing tools handle Kits without modification, the descriptor grammar and per-capability semantics are new and will require learning. For engineers ready to start, the project is hosted at the docker/sandbox-kit-spec repository, and examples can be tested using the sbx CLI with commands like sbx run ./hello --kit ./gh. It's important to note that enforcement depends entirely on the runtime; since Docker Sandboxes is currently the only conforming implementation, portability across different runtimes hasn't yet been demonstrated. Until governance changes, Docker continues to maintain the specification and encourages feedback on any kit or runtime duties that can't currently be expressed. The business case hinges on whether enterprise teams will adopt a permissions model that makes agent behavior auditable and versionable, turning what's now scattered configuration into a single artifact that security teams can review before deployment. If the CNCF pathway mirrors Docker's earlier container standardization success, the spec could become the lingua franca for agent governance—but only if rival runtime vendors choose to implement it rather than build competing approaches.