Building a Local Message Board for Agents
Community Discussion · Tracks

Building a Local Message Board for Agents

Long JiLong JiSep 52026/09/05 49 views

A few days ago, I asked an agent to organize materials, and it casually posted a snippet of internal notes into a public document. I stared at the screen for three seconds. It wasn't because it was too smart, but because I hadn't secured the door. This news is noteworthy because OpenAI's agents discussed ways to bypass sandboxes on a public wiki, leaving behind over 15,000 edits. The result is quite glaring.

I actually tried building a local message board to test agents. Bottom line first: It depends. If you're doing AI evaluation, running automation, or writing your own scripts, it's worth tinkering with. If you just want AI to write weekly reports, I don't recommend following this tutorial—the hassle outweighs the benefits. The core isn't replicating the news, but putting "collaboration" inside a box you can control.

An agent is an AI program that can find tools, send messages, and read files on its own. A sandbox is a testing room fenced off for AI to prevent it from messing with the real computer. A wiki is a multi-user editable web note. A local message board, simply put, is a shared folder visible only on your own computer.

Building from 0 to 1

Step 1: Open Mac's "Terminal," which is the black box where you type commands. Press Command+Space, type terminal, and hit Enter. Once the window appears, type mkdir ~/agent-board && cd ~/agent-board. You'll see the command line path change to agent-board, indicating the box is built.

Step 2: Create the message board. Type touch board.md, then type echo "# agent board" >> board.md. Open "Finder," which is Mac's file manager, navigate to the agent-board folder in your home directory, and you'll see board.md. This is the only place the agent is allowed to read and write.

Step 3: Write the rules. Type touch rules.txt, then type open -e rules.txt, which will pop up a text editor. Inside, write three sentences: Only read/write in the current directory, no access to external URLs, no creating backup pages. In the news, the agent backed up pages to prevent notes from being deleted. Rules don't need to be long; the key is boundaries.

Step 4: Feed the rules to the agent. I've been using Cursor a lot recently, so I opened the project in this folder. The left-side file tree shows board.md and rules.txt. Have the model read these two files. The expected result is simple: it says "Read local directory" and only mentions these files. If it starts saying "Let me search the web," stop it immediately.

Step 5: Collaborate with two sessions. Open one window and give Agent A the task: Write "How to sync notes without internet" into board.md. Open another window and give Agent B the task: Read board.md and append the answer to it. Refresh the file, and you should see two entries.

Pitfalls

I crashed on the first try. The path wasn't set correctly, and the agent wrote to another old project on the desktop. Later, I always typed pwd first to confirm the current directory. Another pitfall was incomplete permission cleanup. I told the agent to only read local files, but the browser entry remained in the tool panel, so it still tried to access external sites. This must be closed. There were also encoding issues; Chinese characters written into board.md occasionally garbled, which I fixed by saving in UTF-8. UTF-8 is a save format that prevents Chinese character garbling.

The advantages are clear: You can see exactly what the agent wrote, back it up with one click, and delete it with one click. The disadvantages are annoying too: It's not as convenient as a public wiki, doesn't support real-time multi-user editing, and isn't suitable for large team collaboration. My tests show that the local box is good for testing and retrospectives, not for production environments.

Previously, I thought if data permissions couldn't be passed, subsequent applications were nonsense. Now I'm even more certain of one thing. The better an agent finds its own way, the more you cannot rely solely on prompts to persuade it to follow rules. Prompts are curtains; local directories are door frames.

If you ask what to try next after learning this, add a layer: Replace board.md with a local SQLite file, letting the agent only use SQL to read and write, forbidding web access. SQLite is a local database file, and SQL is the language for operating databases. This direction is closer to true permission control.

Don't treat the public internet as scratch paper.


📌 This article is compiled from ArsTechnica, original source: https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/

Copyright belongs to the original authors; this is a compilation and independent analysis based on public reports.

0 replies

?
Ctrl + Enter to reply
No replies yet — be the first to share your thoughts