CROSS-CATEGORY: Agent Containment Shipped in Three Unrelated Products in 48 Hours — While PromptArmor Showed Atlassian's Rovo Still Leaking
Within two days, three vendors with nothing in common moved containment from documentation into enforced runtime: Zed enabled OS-level sandboxing of its agent's terminal and fetch tools by default in v1.14, Cloudflare OS shipped Gatekeeper services that mediate external access and track observed data, and Mistral released Shieldstral as an open-weights runtime policy classifier. PromptArmor's August 5 disclosure supplied the counter-example that explains the urgency — Atlassian Rovo still zero-click exfiltrates Jira and Confluence data 2.5 months after disclosure. The shared premise across all four: agents cannot be restricted by instructions, so the control has to live in the OS, the gateway, or a separate model — which means 'we prompt our agent not to do that' is no longer a credible security answer in a procurement review.
↳ Follow the thread