{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:D4GWMA263Q6ZFIROZW5MOF6NVR","short_pith_number":"pith:D4GWMA26","schema_version":"1.0","canonical_sha256":"1f0d66035edc3d92a22ecdbac717cdac4f4ec5dab021d110de7a42df55ce723c","source":{"kind":"arxiv","id":"2603.02277","version":2},"attestation_state":"computed","paper":{"title":"Quantifying Frontier LLM Capabilities for Container Sandbox Escape","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Art O Cathain, Harry Coppock, Jason Gwartz, Jerome Wynne, John Wilkinson, Philippos Maximos Giavridis, Rahul Marchand, Sam Deverett","submitted_at":"2026-03-01T22:47:39Z","abstract_excerpt":"Large language models (LLMs) increasingly act as autonomous agents, using tools to execute code, read and write files, and access networks, creating novel security risks. To mitigate these risks, agents are commonly deployed and evaluated in isolated \"sandbox\" environments, often implemented using Docker/OCI containers. We introduce SANDBOXESCAPEBENCH, an open benchmark that safely measures an LLM's capacity to break out of these sandboxes. The benchmark is implemented as an Inspect AI Capture the Flag (CTF) evaluation utilising a nested sandbox architecture with the outer layer containing the"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2603.02277","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-03-01T22:47:39Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a4867f640aaafd4106d841deca7a6952b9156ced0dd9fab75612bb28ffe6c486","abstract_canon_sha256":"0fa41bb6c6b1261c9e83d2ee75ec648ace5c8235697874bc4ef507eae5f220bf"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-08T01:19:11.232404Z","signature_b64":"ttpULNs16PurT0hfv7449x+xUpVRejg+hZ3G/nv3V5UvGuU4FiSRfANNlki151NdxngNRRNfwhz8JgsfbJzaDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1f0d66035edc3d92a22ecdbac717cdac4f4ec5dab021d110de7a42df55ce723c","last_reissued_at":"2026-07-08T01:19:11.231842Z","signature_status":"signed_v1","first_computed_at":"2026-07-08T01:19:11.231842Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Quantifying Frontier LLM Capabilities for Container Sandbox Escape","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Art O Cathain, Harry Coppock, Jason Gwartz, Jerome Wynne, John Wilkinson, Philippos Maximos Giavridis, Rahul Marchand, Sam Deverett","submitted_at":"2026-03-01T22:47:39Z","abstract_excerpt":"Large language models (LLMs) increasingly act as autonomous agents, using tools to execute code, read and write files, and access networks, creating novel security risks. To mitigate these risks, agents are commonly deployed and evaluated in isolated \"sandbox\" environments, often implemented using Docker/OCI containers. We introduce SANDBOXESCAPEBENCH, an open benchmark that safely measures an LLM's capacity to break out of these sandboxes. The benchmark is implemented as an Inspect AI Capture the Flag (CTF) evaluation utilising a nested sandbox architecture with the outer layer containing the"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2603.02277","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2603.02277/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2603.02277","created_at":"2026-07-08T01:19:11.231905+00:00"},{"alias_kind":"arxiv_version","alias_value":"2603.02277v2","created_at":"2026-07-08T01:19:11.231905+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2603.02277","created_at":"2026-07-08T01:19:11.231905+00:00"},{"alias_kind":"pith_short_12","alias_value":"D4GWMA263Q6Z","created_at":"2026-07-08T01:19:11.231905+00:00"},{"alias_kind":"pith_short_16","alias_value":"D4GWMA263Q6ZFIRO","created_at":"2026-07-08T01:19:11.231905+00:00"},{"alias_kind":"pith_short_8","alias_value":"D4GWMA26","created_at":"2026-07-08T01:19:11.231905+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":5,"sample":[{"citing_arxiv_id":"2607.05743","citing_title":"The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities","ref_index":20,"is_internal_anchor":true},{"citing_arxiv_id":"2606.22504","citing_title":"Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents","ref_index":35,"is_internal_anchor":true},{"citing_arxiv_id":"2605.14859","citing_title":"Do Coding Agents Understand Least-Privilege Authorization?","ref_index":38,"is_internal_anchor":true},{"citing_arxiv_id":"2604.23425","citing_title":"When the Agent Is the Adversary: Architectural Requirements for Agentic AI Containment After the April 2026 Frontier Model Escape","ref_index":31,"is_internal_anchor":true},{"citing_arxiv_id":"2604.11477","citing_title":"OOM-RL: Out-of-Money Reinforcement Learning Market-Driven Alignment for LLM-Based Multi-Agent Systems","ref_index":12,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR","json":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR.json","graph_json":"https://pith.science/api/pith-number/D4GWMA263Q6ZFIROZW5MOF6NVR/graph.json","events_json":"https://pith.science/api/pith-number/D4GWMA263Q6ZFIROZW5MOF6NVR/events.json","paper":"https://pith.science/paper/D4GWMA26"},"agent_actions":{"view_html":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR","download_json":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR.json","view_paper":"https://pith.science/paper/D4GWMA26","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2603.02277&json=true","fetch_graph":"https://pith.science/api/pith-number/D4GWMA263Q6ZFIROZW5MOF6NVR/graph.json","fetch_events":"https://pith.science/api/pith-number/D4GWMA263Q6ZFIROZW5MOF6NVR/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR/action/timestamp_anchor","attest_storage":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR/action/storage_attestation","attest_author":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR/action/author_attestation","sign_citation":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR/action/citation_signature","submit_replication":"https://pith.science/pith/D4GWMA263Q6ZFIROZW5MOF6NVR/action/replication_record"}},"created_at":"2026-07-08T01:19:11.231905+00:00","updated_at":"2026-07-08T01:19:11.231905+00:00"}