Fetching from the wire…
Public story · 2026-08-17 · high
It also fixes two approval bugs and follows Hazmat's OS-level sandbox fix by a week.
Why now: This is the second sandbox-hardening release for AI agents in the same week, arriving a day after 0.21.0 and right behind Hazmat's OS-level fix.
OpenAI shipped Agents SDK 0.21.1 on August 16, one day after 0.21.0, adding Docker sandboxes that can disable networking entirely, per the GitHub release notes.
A network-disabled sandbox can't leak data even if the code inside turns hostile. That matters most for agents running with a user's full login and permissions.
The release also adds run-scoped sandbox working directories, model call timeouts and Modal sandbox resource options.
It fixes two approval bugs too. The core now honors exact call-approval decisions instead of guessing. It also rejects stacked anchors that only partially match instead of letting them slide through.
Hazmat closed the same kind of gap at the operating-system level a few days earlier. Neither project asks whether an agent needs to run with a person's full identity in the first place. Both just build a wall around it after the fact. Watch whether network-disabled sandboxes become the default in the next release, not a setting developers have to find.
Each link below shares sources, entities, or timing with this story.
Agent Plugins partners with OpenAI / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Agent Plugins partners with OpenAI); both cover GitHub, OpenAI; reported by the same outlet (github.com).
OpenAI uses Vercel / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (OpenAI uses Vercel); both cover GitHub, OpenAI; reported by the same outlet (github.com).
LLM uses OpenAI / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (LLM uses OpenAI); both cover GitHub, OpenAI; reported by the same outlet (github.com).
OpenAI uses Claude Code / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI uses Claude Code); both cover GitHub, OpenAI; reported by the same outlet (github.com).
OpenAI released OpenAI Agents SDK / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI released OpenAI Agents SDK); both cover GitHub, OpenAI Agents SDK; reported by the same outlet (github.com).
OpenAI uses Claude Code / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI uses Claude Code); both cover Docker, GitHub, OpenAI; overlapping topics (agent, same).
LangGraph uses OpenAI / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (LangGraph uses OpenAI); both cover OpenAI, OpenAI Agents SDK, SDK; overlapping topics (agent, openai).
OpenAI released OpenAI Agents SDK / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI released OpenAI Agents SDK); both cover OpenAI Agents SDK, Released; reported by the same outlet (github.com).