Blog/Engineering Intelligence··4 min
Claude Fable sold the long-horizon agent. Helix's change center is the DNS fence that refuses loopback.
Anthropic's Fable week is long-horizon agents. Helix on sandbox-runtime lights #522 DNS fence (loopback/private), not release #528; dannycochran owns src/sandbox.
- sandbox-runtime
- anthropic
- dns
- containment
- engineering intelligence

anthropics/sandbox-runtime sits next to a loud public week.
Anthropic's Claude Fable and Mythos 5.1 story is long-horizon agents, product framing, and the containment-escape conversation operators are already routing around (secondary coverage). That is Layer A. Cite the press. Helix did not invent Fable.
Here is the plot twist.
When Helix Explorer indexed the latest merged pull requests on that same sandbox-runtime repo, the Overview latest merge card was #528 Release v0.0.76. The change center Helix lights is not the release card. It is a jail implementation detail: refuse allow-listed hostnames that still resolve to loopback, link-local, or configured private ranges.
The product sold the horizon. The change center sold the fence.
Long-horizon agents are glamorous. DNS fences are not. A hostname on an allow-list that resolves to 127.0.0.1, link-local, or a configured private range is exactly the kind of quiet hole a sandbox has to close if "containment" is going to mean anything once agents start calling out.
Latest merge card: #528 Release v0.0.76 (shawnm-anthropic). The change center Helix lights is #522 Refuse allow-listed hostnames that resolve to loopback, link-local or configured private ranges (dannycochran, Sep 10). Reviewers in Helix: zjw4242 and shawnm-anthropic (both approved). Blast radius: 19 files.
Pulse hot files in the same crop line up with that fence, not with a release blog:
test/sandbox/resolved-address-guard.test.ts(1124 churn)src/sandbox/resolved-address-guard.ts(309 churn)src/sandbox/address.ts(168 churn)
Architecture areas Helix names: src/sandbox (12 files, dannycochran owns, 1043 churn) and test/sandbox (8 files, 1270 churn). The ownership story on the fence surface is blunt: dannycochran is the evidenced author on the resolved-address-guard and address path in this window.
Who showed up in the window
Evidenced experts (Ownership scores Helix showed):
- shawnm-anthropic 3.8
- dannycochran 3.8
- ronleizrowice-ant 2.6
- Reviewers also on the board: zjw4242 1; sylvesterkaczmarek 0.9; dylan-conway 0.9
Also in the three-PR index (release card already covered above; still not the change center):
- #513 Sanitize an unregistered attribution key in every violation producer (ronleizrowice-ant)
Coupling lists 8 repeated pairs. Each pair shows 1 shared pull request only. That is co-change evidence of coordination in a thin window, not a multi-PR weight story and not proof of a strong import graph. Do not inflate it.
Window honesty (numbers late on purpose)
Helix Explorer (signed out) indexed this repo with evidence dated Sep 13. Overview heading asked what changed in the last 8 merges. The latest merge card and activity both say 3 merges in this window · plan cap 8. Do not read this as a 50-limit Scale window. It is a thin Explorer crop.
Helix inference. In this three-PR window, the latest merge card is #528 (release). The change center Helix lights is the resolved-address / DNS fence (#522), sitting on dannycochran-owned src/sandbox, with Pulse churn concentrated in resolved-address-guard tests and implementation plus address.ts.
Hypothesis (not a graph finding). While the public week talks long-horizon agents and containment escape, the merges Helix can see are hardening how an allow-listed hostname is refused when DNS still points at loopback or private space. The evidence does not prove Helix "found" Claude Fable, that dannycochran is a project-wide bus factor outside this window, or that the eight coupling pairs carry strong multi-PR weight. It does show a 3-of-8 Explorer window whose latest merge card is #528, whose change center is #522, whose hot Pulse files are the resolved-address-guard surface, and whose src/sandbox area is owned by dannycochran in-window.
OpenClaw stays our live first-customer demo. This sandbox-runtime package is content flywheel / research secondary: a Layer A press hook plus a Layer B Helix read, not a swap of the demo narrative.
The lesson
When a lab sells long-horizon agents and containment language, ask the unglamorous follow-up: which files are carrying the DNS fence, and who can change them.
For sandbox-runtime, Claude Fable is the public story. In the three PRs Helix could see, the latest merge card is a release (#528). The change center is refusing allow-listed hostnames that resolve to loopback or private ranges (#522), and Helix can name the owner on src/sandbox.
That is the kind of thing you cannot get from the product post alone. It is also the kind of thing you want before you treat "containment" as a finished engineering story.
What would Helix find in your software?
Connect GitHub. Let a thin merge window explain itself, including the jail detail that never made the Fable write-up.

