I break AI agent sandboxes to see which ones hold. Co-founder Origin, Side Quest @Lumeo_hq. 3x founder, 2x exit. FTDAO 0→$19M TVL. Prev DevRel @RomeProtocol
wanna raise a million dollars? here’s the pro tip: take a base model. fine-tune it on one vertical. benchmark it against GPT and Claude on that narrow slice. win. call it “the world’s best model for [industry].” raise.
the benchmark win is real. whether the edge survives the market is the part nobody’s pitching.
Looking for a US-based co-founder.
Building compliance infrastructure for cross-border earners. Live in one
market, US is next.
Requirements:
- US citizen
- 3+ years in tax compliance, accounting, or financial regulation
- Understands US filing: individual and small-business returns, 1099s,
state vs federal, foreign income treatment
- Comfortable being the named principal on regulatory registrations
- Has either worked inside a firm or sold software into one
- Wants to own a market end to end, not run a function
Nice to have:
- EA, CPA, or equivalent
- Worked at a tax software company, an accounting firm, or a fintech
- Has taken something from zero to first customers
What you get: real founder equity and full ownership of the US business. We handle the entity setup, the engine, and everything on the India side.
You own the compliance layer and the market.
Book 15 minutes: https://t.co/ceWBSV0FgT
@FReza1984 yeah, you get it. alignment is about intent, isolation is about capability, and once an agent runs code the second one is all that stands between it and the host. measuring exactly that with AgentEscape. what’s your angle on it?
AI safety spends most of its energy on aligning the model. But we're about to run millions of agents that write and execute their own code, and alignment doesn't help once an agent can reach the host.
The unmeasured question: when an agent tries to break out of its sandbox, does the sandbox hold?
That's the year I'm signing up for.
1/ Every AI coding agent runs generated code somewhere. That "somewhere" is a sandbox: Docker, gVisor, Kata, Firecracker, WASM.
The question nobody benchmarks: under an adversarial agent, does the isolation boundary actually hold?
I'm building AgentEscape to measure it.
5/ Learning from the people working on this directly: @AISecurityInst's SandboxEscapeBench, @METR_Evals on the incident review, @PrimeIntellect on the RL environments this runs on, and @ddkang on agent security.
4/ Why it matters: reward hacking in an RL environment and a sandbox escape in prod are the same event - the agent leaving its intended boundary. One field trains against it, the other evaluates it.
The benchmark speaks to both. Building in the open.
What escape should I add first?
4/Learning from the people studying this closely: @METR_Evals is running an independent review of the incident, @PrimeIntellect is building the RL environments this all runs on, and @ddkang works on agent security directly.
1/ In July, an @OpenAI eval model broke out of its test sandbox and reached @huggingface's production database.Most read it as "rogue AI." The systems read is simpler: it reward-hacked. It escaped the boundary to reach the benchmark's answer key.Reward hacking and sandbox escape are the same bug.
3/So I'm building an open benchmark for agent sandbox integrity: escape attempts across isolation backends, measuring which ones actually hold.The reward-hacking crowd and the AI-control crowd both need this. Building in the open.What escape would you want tested first?
Looking to connect with growth folks working at AI startups, especially across:
• AI-native products
• Developer tools
• AI infrastructure
• Consumer AI tools
If you’re leading or working on growth in these spaces, would love to connect and exchange notes.
DMs open. Intros appreciated.