GitGuardian and Docker pair sandboxed coding agents with secret scanning
GitGuardian published a Docker Sandbox Mixin Kit that auto-installs ggshield and its AI hooks inside isolated agent environments, combining Docker's microVM boundary with real-time credential scanning.
Docker Sandboxes give coding agents an isolated microVM to work in. GitGuardian's new Mixin Kit fills in the other half of the problem: watching the credentials that flow through the agent while it works. The company announced the partnership this week, publishing a Docker Sandbox Mixin Kit that automatically installs its ggshield CLI and configures AI hooks for the coding assistant inside the sandbox.
The idea is that agent security needs two controls, not one. Docker Sandboxes handle the environment boundary: each sandbox runs in an isolated microVM where the agent can execute commands, install dependencies, and use developer tools without unrestricted access to the host machine. Workspace scoping limits which local files exist from the agent's perspective, network policy controls where it can connect, and sensitive credentials stay outside the microVM, injected by Docker's host-side proxy only when an approved request needs them.
Three hooks around the agent's work
GitGuardian handles the credential layer inside that boundary. The mixin wires up three hooks from ggshield's AI coding tool integration. The prompt-submission hook scans a developer's prompt for secrets before it reaches the model and blocks it when one is detected, which protects the common workflow of pasting a config file or log output into a conversation while debugging. The pre-tool-use hook scans file reads, shell commands, and MCP calls before the agent executes them and blocks the action when a secret is detected. The post-tool-use hook scans tool output and fires a desktop notification when a secret appears in a result, so the developer knows sensitive material entered the workflow and can respond.
The numbers behind the launch are stark. GitGuardian says its research found an average of roughly 150 secrets per developer endpoint in its early access program, with some machines holding thousands, and that around 40% of the high and critical secrets discovered appeared in AI tool directories and log files. Those are company-reported figures from its own research, not an independent audit.
The published kit ships mixins for Claude Code, Codex, GitHub Copilot, and Cursor. Setup runs through Docker Hub: pick the mixin for your assistant, set your GitGuardian API key with sbx secret set gitguardian so the real credential stays outside the sandbox, then launch the sandbox with the mixin enabled. Teams that do not run Docker Sandboxes can install the same ggshield hooks directly into their coding tools for the same prompt and tool-call checks.
Mixins exist because an empty sandbox is a sandbox developers will not use. Docker's own framing is the paved-road argument: if engineers have to reinstall packages, rebuild configuration, and re-supply credentials every time they enter an isolated environment, running the agent directly on the host becomes the easier path. The GitGuardian mixin is a bet that credential protection has to arrive with the environment, configured, or it will not arrive at all.