Supply Chain - PyPI Install of sandbox-cli-sdk
This detects when an AI agent, or a process it started, runs a Python package manager to install or execute the package sandbox-cli-sdk. That package is a legitimate developer tool for running commands inside isolated containers, but it can also give an agent a quiet way to run code outside normal host monitoring.
How the attack works
An agent (or something it spawned) calls pip, uv, or a similar Python package manager with an install or run command that names sandbox-cli-sdk. Installing the package executes the publisher's setup code on the local machine, and once installed, sandbox-cli-sdk gives the agent a built-in way to launch commands inside sandbox-cli containers. Because container activity is often less visible to host-based security tools, this creates a path for an agent to execute payloads with reduced oversight. The rule only looks at a single command line: it fires when an install/run verb and the exact package name both appear together, and does not fire for uninstalls, inspection commands, or a plain text mention of the name.
Netzilo detection
Netzilo reports this behaviour when it is observed.
- Signature ID
- 4f3c9b2e-7d81-4a56-9c0f-2b6e5d18a7c3
- Severity
- Medium
Why it matters
An organization risks an agent quietly gaining a container-execution capability that runs outside normal host visibility, and running arbitrary third-party publisher code during install. This is one narrow signal — package installation — not proof of a full compromise.
What you can do
- →Confirm whether a human explicitly requested this package before treating the alert as suspicious.
- →Review whether your agents are permitted to install new dependencies unsupervised, and restrict that ability if not required.
- →Check logs and container runtime activity for anything the agent ran via sandbox-cli after installation.
- →Maintain an allowlist of approved packages for agent-driven environments and alert on installs outside it.
Known benign look-alikes
- A developer or an agent acting on an explicit human request deliberately installing sandbox-cli-sdk as a project dependency.
- CI/CD or container build steps that install the project's declared dependency set with the package named inline on the command line.
- Environment reconstruction after a wipe (recreating a virtualenv, `uv sync` fallbacks that materialise the package name on the command line).
- Security or supply-chain researchers reproducing the package installation in a disposable environment for triage.
- Package pinning / upgrade automation (Dependabot-style bots, `poetry add sandbox-cli-sdk@^x.y`) run locally by a developer.