Stage 11 of 11 · Advanced Agents · 3 min · Reviewed Aug 2026
Advanced Agents: Coding, Sandboxes, Filesystems, Multimodal
Coding agents, sandboxed execution, filesystem tools, and multimodal inputs are how 2026 products actually work. This is the end of the path, not a shortcut around loops, tools, evals, and reliability.
- Coding agents
- Sandboxes
- Filesystems
- Multimodal
What you learn
How modern autonomous AI systems are built — and why they still need the previous ten lessons.
Coding agents are tool loops on a repo
A coding agent plans, reads, patches, runs tests, and repeats. The repository and the test runner are the environment. Cursor, Claude Code, Codex-class tools, and hosted “Devin-like” workers all instantiate that loop with different UX and isolation.
The product is the diff plus the trace, not the chat. If you cannot review the patch, you cannot ship the agent.
Interactive
Coding Agent Loop
Plan
Agent reads the task and produces a step-by-step plan of files to change.
Filesystems are powerful tools
Read, write, glob, grep, apply-patch: these are the real APIs. Scope them to a workspace. Ban .env and secrets paths. Prefer apply-patch over rewriting whole files. Watch the working tree size; agents will write junk if you let them.
A filesystem tool without a sandbox is shell as a service.
allow: read, write, glob, grep, apply_patch
deny: .env, **/*secret*, ~/.ssh
workspace: /tmp/run-8f2a
network: noneVisual
Filesystem Tool Permissions
Filesystem tools are scoped to a workspace with an explicit allow/deny list. Without a sandbox, filesystem access is shell-as-a-service.