Sandboxing and isolation
Runtime containment and code execution security
Sandbox tools 38
- Secure, kernel-enforced sandbox CLI agithub.com
- OpenSandbox is a general-purpose sandgithub.com
- Python read-only sandbox for LLM agents angithub.com
- A minimal, secure Python interpreter writtgithub.com
- Postgres Sandboxpostgres.new
- Claude "File creation" is actually a sandboxed code execution environment and hasx.com
- acl-proxy - Rust ACL-aware HTTP/HTTPS proxy with URL policy enginegithub.com
- Agent Safehouse - macOS kernel-level sandboxing for LLM coding agentsagent-safehouse.dev
- Box by ASCII - cheap persistent Linux VM sandboxes for AI agentsbox.ascii.dev
- Bromure - disposable Linux VM sandboxes on macOS for AI coding agents and browsinggithub.com
- clawker - self-hosted AI coding agent sandbox in Docker with egress firewallgithub.com
- cloudflare/computer - virtual filesystem and sandboxed execution environment for agentsgithub.com
- Coder - self-hosted, governed environments for running AI coding agents at scalecoder.com
- Cordium - open-source identity-based sandbox platform for developers and AI agentsgithub.com
- CubeSandbox - secure lightweight sandbox for AI agentsgithub.com
- Dan Guido on running Claude Code in YOLO mode safely with the Trail of Bits devcontainerx.com
- Daytona - Secure Infrastructure for Running AI-Generated Codedaytona.io
- Docker Sandboxes - Run Claude Code and Coding Agents Unsupervised but Safelydocker.com
- dyana - sandbox for loading, running and profiling ML models, pickles and other filesgithub.com
- exe.dev - disposable sandbox VMs for AI agentsexe.dev
- fend - sandboxed micro-VM runtime for npm install and dev scriptsgithub.com
- hazmat - OS-level containment for AI coding agentsgithub.com
- httpjail - HTTP and HTTPS request filter and network isolation for processesgithub.com
- iron-proxy v0.23.0 - egress firewall for untrusted workloadsgithub.com
- jailer - eBPF-based mandatory access control process jailing for Linuxgithub.com
- John McBride introduces stereOS, a hardened NixOS-based operating system for sandboxing AI agentsx.com
- Landlock - unprivileged sandboxing for Linuxlandlock.io
- Lume - macOS VM sandbox for AI agentscua.ai
- mezz - self-contained wifi sandbox for inspecting IoT devicesgithub.com
- MXC - Microsoft eXecution Container for sandboxing untrusted model output and toolsgithub.com
- netfence - eBPF network egress allowlisting daemon for VMs and containersgithub.com
- sandbox-probe - agentic sandbox enumeration and escape testing for AI coding agentsgithub.com
- sandcat - Docker dev container sandbox for AI agents with mitmproxy network rules and secret injectiongithub.com
- shuru - local-first microVM sandbox for AI agentsshuru.run
- SlicerVM - real Linux microVMs for AI sandboxesslicervm.com
- traffico - eBPF traffic shaping with network intent guardrails for agent workloadsgithub.com
- vmux - stateful sandboxes for agentsvmux.sdan.io
- yolobox - sandboxed AI coding agents in a containeryolobox.dev
Containerization 21
- Docker Desktop 4.40 Release - Dockerdocker.com
- Docker Labs: GenAI No. 19linkedin.com
- Containerize your agents!discord.gg
- Docker Sandboxes: Run Agents in YOLO Mode, Safelydocker.com
- Docker Sandboxesdocs.docker.com
- Chainguard Images - minimal hardened container imagesimages.chainguard.dev
- Chainguard OS Whitepaperget.chainguard.dev
- Containerize your agents! - Daggeryoutube.com
- Copacetic - directly patch container image vulnerabilitiesproject-copacetic.github.io
- Copy Fail in Kubernetes: RuntimeDefault Did Not Block AF_ALG - CVE-2026-31431juliet.sh
- Docker-OSX - run macOS in Docker for security researchgithub.com
- Greg Castle on converting GKE system containers to non-root - KubeCon EU talk summaryx.com
- Kasm Workspaces - container streaming and remote browser isolationkasmweb.com
- Kubernetes security: Safeguarding your container kingdom - Red Canaryredcanary.com
- macOS Containers Initiative - native container support and isolation on macOSmacoscontainers.org
- Minimus - free hardened container images with near-zero CVEsminimus.io
- oci-seccomp-bpf-hook - OCI hook to trace syscalls and generate seccomp profilesgithub.com
- Orchard - native macOS UI for Apple Containers with sandboxed agentsorchard.andon.dev
- seccomp-profiler - eBPF tool that generates per-container seccomp profilesgithub.com
- Securing the Container World with Policies: acjs and ctrdacbughunters.google.com
- tank-os - Fedora bootc image for running OpenClaw as a rootless Podman workloadgithub.com
Guides and discussion 12
- YOLO in the Sandbox – Voratiqvoratiq.com
- KiloClaw Security White Paper244051090.fs1.hubspotusercontent-na2.net
- A field guide to sandboxes for AIluiscardoso.dev
- Agent Safety is a Box - Marc Brookerbrooker.co.za
- Daniel Von Fange on secure crypto dev needing 4 isolated computers - no npm, VS Code or agentsx.com
- Escaping Google Cloud Application Integration Sandbox: Straight into Borgnopnop.pro
- In sandboxes we shouldn't trust - limits of sandboxing AI agentsembroidery.io
- Jennifer Marsman on sandboxing OpenClaw with Microsoft Execution Containersx.com
- Philipp Schmid on sandbox network allowlists and egress-proxy credential injectionx.com
- Simon Willison on httpjail - HTTP sandboxing for coding agentssimonwillison.net
- VMs won't contain cyber-capable agentsblog.trailofbits.com
- Your Container Is Not a Sandbox - The State of MicroVM Isolation in 2026emirb.github.io