Read-Only Access to Shared Package Caches Can Enable Inter-Sandbox Communication
Ishuah Kariuki · Team Cache Flow
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
This project demonstrates that read-only access to shared package infrastructure can still enable communication between evaluation sandboxes.
Reviews
Careful, well controlled, and honest about its own limits. Matched experimental arms with the right ablations, a protocol frozen and hashed before the run, and every reported figure reproducing exactly on independent recomputation from the raw latency logs. The tests guard precisely the errors this design invites — calibration leaking into the held-out split, the decoder being fitted on the wrong data. One arm produced a result the paper could not explain, and it was left unexplained rather than fitted to a story.
The limits are real and mostly acknowledged: a single quiet host, no production registry, no competing traffic, and arms that replay the same source bits rather than sampling independently.
The one thing worth pressing is coordination. The channel works because both ends already agree on the protocol. Whether two independently operating agents would converge on it unprompted is the question the framing invites and the experiment does not reach. Either test that, or bring the abstract closer to the configuration-specific claim the body actually makes.
Read full reviewShow less
I liked this experiment! The central point is simple but important: "read-only" does not mean "cannot influence shared state." The shared-cache result makes that distinction very tangible, especially because package infrastructure was relevant to the motivating incident.
The controls were probably the strongest part for me. Using the same frozen bit sequence across shared versus private caches, warm versus lazy conditions, and online versus offline conditions makes it much easier to understand what is actually producing the signal. Getting 24/24 held-out bits in the shared/lazy condition, alongside the origin-fetch evidence, is a convincing demonstration of the mechanism you are claiming.
I also appreciated that you did not interpret the weaker control results as proof of isolation. In particular, the 16/24 result in the private-cache condition is left unresolved instead of being hand-waved away. That kind of restraint makes me trust the rest of the analysis more.
My main question is how much this generalizes beyond the deliberately amplified testbed. The 200 ms synthetic upstream delay makes the channel especially visible, and the experiment uses one host, scripted clients, serialized requests, and one cache implementation. I would be very interested in follow-up experiments with realistic package latency and noise, concurrent tasks, and different package-cache implementations.
Read full reviewShow less
Cite this project
@misc{kariuki2026readonly,
title = {{Read-Only Access to Shared Package Caches Can Enable Inter-Sandbox Communication}},
author = {Ishuah Kariuki},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/readonly-access-to-shared-package-caches-can-enable-intersandbox-communication-zlfa}},
url = {https://apartresearch.com/sprints/projects/readonly-access-to-shared-package-caches-can-enable-intersandbox-communication-zlfa}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …