Least-privilege filesystem sandbox & context guardrails for AI agents
-
Updated
Feb 3, 2026 - Go
Least-privilege filesystem sandbox & context guardrails for AI agents
Per-process OS-level sandboxes for Go: macOS sandbox-exec (SBPL/seatbelt) + Linux bubblewrap, applied to an *exec.Cmd via a declarative Profile. Non-optional SBPL literal validator; narrowed bwrap mounts + namespace unsharing.
Add a description, image, and links to the bwrap topic page so that developers can more easily learn about it.
To associate your repository with the bwrap topic, visit your repo's landing page and select "manage topics."