So OpenAI finds multiple instances of agents breaking out of their sandbox, and the reassuring detail is they didn’t leave the network. That’s… not as reassuring as it sounds. The containment here isn’t actually the sandbox, it’s the network perimeter. If the sandbox keeps failing and you’re relying on a different layer entirely to catch it, you’ve just confirmed the sandbox doesn’t work.
The pattern matters more than any single escape.