seccompiler
seccomp-bpf jailing
landlock
LSM helpers
hyperlight-host
A lightweight Virtual Machine Manager that can be hosted in an application to safely run untrusted or code within a VM partition with very low latency and overhead
microsandbox
microsandboxis the core library for the microsandbox project
nono-rs
The opposite of YOLO - a capability shell for AI agents
ai-jail
Sandbox for AI coding agents (bubblewrap on Linux, sandbox-exec on macOS)
build-wrap
Help protect against malicious build scripts
cranelift-module
Support for linking functions and data with Cranelift
landstrip
Sandbox for coding agents with parametrized state
nono
Capability-based sandboxing library using Landlock (Linux) and Seatbelt (macOS)
strict-path
Secure path handling for untrusted input. Prevents directory traversal, symlink escapes, and 19+ real-world CVE attack patterns.
hyperlight-component-util
Shared implementation for the procedural macros that generate Hyperlight host and guest bindings from component types
monty
A sandboxed, snapshotable Python interpreter written in Rust
secure-exec-kernel
Shared kernel plane for secure-exec native and browser sidecars
sandlock-cli
CLI for sandlock process sandbox
stakpak
Your DevOps AI Agent. Generate infrastructure code, debug Kubernetes, configure CI/CD, automate deployments, without giving an LLM the keys to production.
sbexec
Run commands in a macOS sandbox with supply chain attack protection
hakoniwa
Process isolation for Linux using namespaces, resource limits, cgroups, landlock and seccomp
oops-sh
Undo for your terminal: run any command in a sandbox, then undo or commit it. Installs the
oopsbinary (Linux via OverlayFS, macOS via APFS snapshots; other platforms refuse to run rather than run unsandboxed).
secure-exec-bridge
Shared bridge contracts between the secure-exec kernel and execution planes
runsc-sentry-guard
An ultra-lightweight active incident response daemon for runsc (gVisor) sandboxes
agentos-sidecar-protocol
Shared Secure Exec sidecar wire protocol and frame helpers
agentos-bridge
Shared bridge contracts between the secure-exec kernel and execution planes
vtcode
A Rust-based terminal coding agent with modular architecture supporting multiple LLM providers
ronly
Read-only sandbox for untrustworthy agents
secure-exec-v8-runtime
V8 isolate runtime for secure-exec guest JavaScript execution
harness-hat
Docker-backed development sessions with proxy-mediated network policy
tartarus
CLI tool wrapping bubblewrap to run proccesses sandboxed to not be able to write to external directories
mknight
A user-space sandbox watcher that stops runaway malloc loops from freezing your machine, with an educational post-mortem
zerobox-sandboxing
Sandbox any command with file, network, and credential controls
hyperlight-wasm
that enables wasm modules and components to be run inside lightweight Virtual Machine backed Sandbox. It is built on top of Hyperlight.
syd
rock-solid application kernel
rfs_tester
package allows you to create a temporary directory for testing purposes. You can use it to perform tests related to file operations. After the tests are finished, the temporary directory will be deleted automatically
adk-code
Code execution substrate for ADK-Rust — typed executor abstraction, sandbox policy model, and built-in execution backends
confinery
command-line interface
hyperlight-common
Hyperlight's components common to host and guest
gigacode
Sandbox Agent CLI with OpenCode attach by default
ferroday-cage
Run a command inside an unprivileged Linux sandbox: fresh namespaces, a provided root filesystem, and a clean environment, established in pure Rust against the kernel
agentos-v8-runtime
V8 isolate runtime for secure-exec guest JavaScript execution
secure-exec-execution
Native execution plane scaffold for secure-exec
adk-sandbox
Isolated code execution runtime for ADK agents
muthr
Zero-trust sandbox for local inference and secure AI coding agent runtimes
capsicum
intuitive Rust bindings for the FreeBSD capsicum framework
a3s-box-netproxy
macOS userspace network proxy for A3S Box libkrun VMs
agentos-sidecar
Native Agent OS sidecar binary
tibet-airlock-kernel
Hardened Rust execution kernel for TIBET airlock — microVM sandbox, kernel isolation in <10ms, cryptographic proof of every execution. Bolle API beneath the Python tibet-airlock operator surface.
heimdall-linux-sandbox
Linux sandbox backend for Heimdall using bubblewrap and namespaces
heimdall-sandbox-policy
Policy document types and filesystem policy materialization for Heimdall
agentos-client
High-level Rust client SDK for the Agent OS native sidecar (1:1 port of the TypeScript AgentOs client)
sandlock-ffi
C ABI for sandlock process sandbox
fluers-core
Core agent primitives and model abstractions for Fluers (port of pi-agent-core + pi-ai)
hyperlight-js
that enables JavaScript code to be run inside lightweight Virtual Machine backed Sandbox. It is built on top of Hyperlight
cylo
Secure multi-language code execution service
wasmer-wasix
WASI and WASIX implementation library for Wasmer WebAssembly runtime
mlua-batteries
Batteries-included standard library modules for mlua
agentos-build-support
Build script helpers for secure-exec crates
wasmsh-runtime
Shared shell runtime core for wasmsh (standalone and Pyodide builds)
rattler_build_script
Script execution and sandbox configuration for rattler-build, supporting bash, cmd, python, and other interpreters
sbe-core
Core library for sbe — cross-platform sandbox executor for supply chain defense
secure-exec-vm-config
Shared Secure Exec VM creation JSON config DTOs
voltaria-sdk
Rust SDK for voltaria_api generated by Fern
agentos-vfs
Secure Exec virtual filesystem backends
path_jail
A secure filesystem sandbox. Restricts paths to a root directory, preventing traversal attacks.
fluers-runtime
The Fluers agent harness: agent definition, sessions, skills, sandbox, events
astrid-vfs
Virtual File System and Capability sandbox for Astrid agent runtime
agentos-actor-uds-client
Internal AgentOS client for Rivet actor SQLite over Unix sockets
arcbox-helper
Privileged helper daemon for host mutations (routes, DNS, sockets)
secure-exec-sidecar
Native Secure Exec sidecar runtime
arcbox-dhcp
Lightweight DHCP server and IP allocator for ArcBox
tinysandbox
Ultra-minimal Linux-like sandbox for AI agents: shell, coreutils, VFS, and a Wasmtime-hosted JS runtime in one crate
podcell
Podman-based development environment manager
krunai
Create microVMs for running AI agents
heimdall-core
Core Heimdall sandbox runtime orchestration and execution types
rattler_sandbox
run executables in a sandbox
sandlock-core
Lightweight process sandbox using Landlock, seccomp-bpf, and seccomp user notification
zapcode-core
A minimal, secure TypeScript subset interpreter — parse, compile, execute, snapshot
cellos-supervisor
CellOS execution-cell runner — boots cells in Firecracker microVMs or gVisor, enforces narrow typed authority, emits signed CloudEvents
agent-os-kernel
Shared kernel plane for Agent OS native and browser sidecars
agent-os-v8-runtime
V8 isolate runtime for Agent OS guest JavaScript execution
secure-exec-sidecar-protocol
Shared Secure Exec sidecar wire protocol and frame helpers
libturnstile
Seccomp-unotify access tracer and namespace-based sandboxing library
zerobox-windows-sandbox
Sandbox any command with file, network, and credential controls
arcbox-dns
DNS packet parsing and response building for ArcBox (no platform deps)
tetherscript
A dynamically-typed scripting language with Rust-style ownership, implemented as a bytecode VM in Rust
hl-engine
Safe Rust lifecycle API for the standalone HL Linux guest engine
pkgbob
A pkgsrc package builder
microsandbox-portal
microsandbox-portalimplements the side car program for executing code and commands in a microsandbox
offload
Flexible parallel test runner with pluggable cloud providers
lumen-sqlite-mcp
An MCP server for storing and manipulating structured data using SQLite
shack-gateway
Progressive-discovery, security-hardened MCP gateway and aggregator
microsandbox-migration
Database migrations for the microsandbox project
hyperlight-unikraft
Embedded Hyperlight host for running Unikraft unikernels
sandbox-agent
Universal API for automatic coding agents in sandboxes. Supports Claude Code, Codex, OpenCode, and Amp.
microsandbox-protocol
Wire protocol types and serialization for the microsandbox project
bjail
A minimal bubblewrap-based sandbox CLI for Linux
rappct
Rust AppContainer / LPAC toolkit for Windows (profiles, capabilities, process launch, diagnostics)
arcbox-protocol
Protocol definitions for ArcBox (ttrpc/protobuf)
microsandbox-utils
Shared constants and utilities for the microsandbox project
procjail
Process sandbox for running untrusted code - Linux namespaces, seccomp, firejail, bubblewrap, rlimits
zerobox-utils-string
Sandbox any command with file, network, and credential controls
presto-pasta
User-mode NAT datapath for sandboxes: L2 tap to native host sockets
agent-os-client
High-level Rust client SDK for the Agent OS native sidecar (1:1 port of the TypeScript AgentOs client)
secure-exec-vfs
Secure Exec virtual filesystem backends
outl-exec
Code-block execution engine for outl: trait Runtime + sandbox + idempotent result subblock
microvm-runtime
Firecracker microVM driver for decentralized Tangle operators — pure-Rust primitive, no service, no auth, no business logic
secure-exec-client
Rust client transport for the Secure Exec native sidecar
arcbox-error
Common error types for ArcBox
sboxd
Policy-driven command runner for sandboxed dependency installation
zerobox-linux-sandbox
Sandbox any command with file, network, and credential controls
zerobox-utils-rustls-provider
Sandbox any command with file, network, and credential controls
rstrict
A lightweight CLI to securely exec Linux processes inside the Kernels Landlock LSM sandbox for filesystem and network access control
microsandbox-cli
CLI binary for managing microsandbox environments
rustwide
Execute your code on the Rust ecosystem
garden-tools
Garden grows and cultivates collections of Git trees Garden lets you define and run commands over collections of configuration-defined multi-worktree Git environments
arcbox-constants
Shared protocol and runtime constants for ArcBox
gommage-cli
Gommage command-line interface
microsandbox-metrics
Shared-memory live metrics registry for microsandbox
astrid-capsule
Core runtime management for User-Space Capsules in Astrid OS
hardened-malloc
Global allocator using GrapheneOS allocator
zerobox-utils-absolute-path
Sandbox any command with file, network, and credential controls
hanzo-sandbox
OS-level sandbox for subprocesses spawned by hanzo (code execution, tools)
kavach
Sandbox execution framework — backend abstraction, strength scoring, policy engine, credential proxy, and audit hooks
secure-exec-build-support
Build script helpers for secure-exec crates
agentos-vm-config
Shared Secure Exec VM creation JSON config DTOs
mockforge-plugin-loader
Plugin loader with security sandboxing and validation for MockForge
shuru-sdk
Async Rust SDK for Shuru microVMs
agent-os-bridge
Shared bridge contracts between the Agent OS kernel and execution planes
safe-shell
Run any command in a secret-aware OS-level sandbox
microvm-warm-pool
Pre-restored Firecracker microVM pool harness for fast warm handoff. Built on top of microvm-runtime.
containerd-shim-wasm
building containerd shims for wasm
omnilua
Every Lua, everywhere — pure-Rust Lua 5.1–5.5, suite-passing, LuaRocks-compatible, wasm-ready
shuru-store
NBD-backed storage layer for shuru microVMs
confinery-sandbox
Platform sandbox engine for Confinery: namespaces, seccomp, Landlock, Job Objects
shuru-darwin
Virtualization.framework bindings for shuru
helm-sdk
Rust SDK for HELM — fail-closed tool calling for AI agents
perspt-sandbox
Sandboxed command execution for Perspt
microsandbox-network
Networking types and smoltcp engine for the microsandbox project
aa-sandbox
WebAssembly/WASI sandbox runtime for Agent Assembly tool execution
hexmake
Run a multi-step build with caching
brokk-anvil
Anvil: Rust ACP server with first-run setup for Codex, Ollama, and OpenRouter
tnk
Zero-trust sandbox for local inference and secure AI coding agent runtimes
orchestrator-runner
Command runner, sandbox, output capture, and network allowlist
zerobox-utils-pty
Sandbox any command with file, network, and credential controls
agentos-protocol
Agent OS extension protocol types
styrolite
Lightweight, programmatic sandboxing tool
littrs
A lightweight, embeddable Python sandbox for LLM tool execution
eryx
A Python sandbox with async callbacks powered by WebAssembly
fuselage
Linux CLI tool for running commands with ephemeral, namespace-private filesystems
microsandbox-agentd
Guest init process and agent daemon for microsandbox microVMs
a3s-box-sdk
Rust SDK for a3s-box direct runtime-backed management APIs
room-sandbox
Dockerized multi-agent sandbox for room
razel
a command executor with caching for data processing pipelines
peon-core
The zero-trust engine driving the Peon workspace, providing dual-layer sandboxing and dynamic Casbin whitelisting
sema-core
Core types and environment for the Sema programming language
boxxkite-client
Rust client for a hosted boxxkite control-plane (sandboxes, exec, files, audit log, human takeover)
microsandbox-db
Shared database entity definitions and connection helpers for the microsandbox project
arbox
Docker-based agent sandbox: a skinny chroot of the host for running coding agents alongside your normal workflow
agent-os-execution
Native execution plane scaffold for Agent OS
metactl
v2 reference kernel and JSON-RPC service
microsandbox-server
microsandbox-serverimplements the sandbox server responsible for orchestrating sandboxes
sbe-proxy
Domain-filtering HTTP CONNECT proxy for sbe sandbox
birdcage
Cross-platform embeddable sandbox
zagens-windows-sandbox
Windows native sandbox (restricted token + ACL + WFP) for Zagens exec_shell
glycin-ng
Permissively-licensed Rust image decoder library with in-process sandboxing
wildling
Pattern based string generator library and CLI
astrid-mcp
MCP client with server lifecycle management for Astrid
childflow
A per-command-tree network sandbox for Linux
agentos-sidecar-browser
Browser Agent OS sidecar wrapper
arcbox-logging
Shared logging infrastructure: tracing init, size-based rotation, JSON + human-readable output
mem-isolate
Contain memory leaks and fragmentation
firkin-e2b-contract
E2B-compatible sandbox contract types for the firkin Rust containerization library
lua-types
omniLua’s core Lua value and error types — internal crate; depend on
omnilua
firkin-envd
Protocol-level envd process and filesystem contracts for Firkin data planes
microsandbox-runtime
Runtime library for the microsandbox sandbox process and microVM entry points
tibet-zip-airlock
tibet-zip Airlock: sandboxed decompression with eBPF kernel enforcement
shuru-proto
Shared wire protocol for shuru host/guest communication
kiln-cli
Command-line interface for kiln
tinman
Deterministic black-box testing framework for CLIs and full-screen TUIs, webrat/capybara/selenium for terminals. Drives real programs through a PTY under a Bubblewrap sandbox. Early prototype.
microsandbox-agent-client
Transport-agnostic client for the microsandbox agent protocol
firkin-template
Template build execution for the firkin Rust containerization library
nono-cli
CLI for nono capability-based sandbox
webcentral
A reverse proxy that runs multiple web applications on a single server with on-demand startup, sandboxing, auto-reload, and Let's Encrypt certificates
cellos
— narrow-authority Rust execution cells with kubectl-style CLI.
cargo install cellosships the cellctl operator tool. cellos-server and cellos-supervisor publish separately.
clawstainer
Lightweight isolated Linux environments for AI agents
bulkhead
Hardened devcontainer CLI for local agent work
cersei-vms
Sandbox & VM isolation for the Cersei coding-agent SDK
mino
Secure AI agent sandbox using rootless containers
orcs-auth
Permission primitives for ORCS: Capability, Session, SandboxPolicy, PermissionPolicy
sparrow-config
Configuration, provider registry, auth/credential store, permissions, hooks, sandbox and humanize layer for Sparrow
apohara-agentguard
Deterministic, offline, no-model safety hook + local seccomp+Landlock sandbox + input firewall for Claude Code
firkin-e2b-server
Local E2B-compatible control plane server for the firkin Rust containerization library
cage-bro
Sandboxed execution environment for AI agents — single binary with browser, shell, code, files, and MCP
langshell
Rust SDK for building stateful, capability-scoped LangShell runtimes
uira-core
Shared types, events, protocol definitions, and configuration loading for Uira
reeve
Allowlist-first runtime for Rhai automation scripts
aerolvm-sdk
SDK for the Aerol.ai MicroVM sandbox API
xript-runtime
Rust runtime for xript. Sandboxed JavaScript execution via QuickJS.
blinkvm-shared
Shared Blink protocol types and constants
gaol
OS-level application sandboxing library
relon-cap
Leaf crate holding Relon's canonical capability data types (CapabilityBit / NativeFnGate / Capabilities)
zerobox-network-proxy
Sandbox any command with file, network, and credential controls
watasu
Rust SDK for Watasu
rink-sandbox
limiting memory usage and time spent of code, and allowing interrupts (ctrl+C)
aegis-security
Command safety and security checks for Aegis
defect-sandbox
Sandboxing and command execution policy primitives for the defect agent
apiari-codex-sdk
Rust SDK for the Codex CLI — spawn and stream codex exec sessions
skilllite-fs
SkillLite FS: centralized file read/write/search_replace
agentkernel
Run AI coding agents in secure, isolated microVMs
rullama-sandbox
Container-based sandboxing (Docker/Podman/host) for tool execution in the rullama framework
firkin-benchmark
Benchmark targets and evidence writers for the firkin Rust containerization library
tartarus-api
Structured API for sandboxing system (currently utilizing
bubblewrap)
dellingr
An embeddable, pure-Rust Lua VM with precise instruction-cost accounting
vpod
Lightweight, secure sandboxes for untrusted processes
agntcy-shadi-cli
Command-line interface for SHADI policy, secrets, memory, and SLIM operations
novmforbroadcom
VM detection library – detect hypervisors, sandboxes, and virtual machines with syscall-spoofed Windows NT calls (Hell's Gate) to evade AV/EDR hooks
afterburner-afb
Afterburner .afb package format — reproducible, content-addressed pack/unpack with sandboxed-manifest preservation
tarnish
Process isolation library with automatic panic recovery for running untrusted Rust code
wai-bindgen-wasmer
Generate WAI glue for a Rust Wasmer host
sail-rs
Official Rust SDK for Sail: create and drive sailboxes (sandboxed cloud VMs) with lifecycle, streaming exec, file transfer, and ingress
agentignore
FUSE filesystem that hides files matching .agentignore rules from processes - control what agents can see while building apps
agent-os-sidecar
Native Agent OS sidecar scaffold
painless-belt
Run a command in a macOS sandbox with sensible defaults
libkrun-sys
FFI bindings to libkrun and libkrunfw
runok
Command execution permission framework for LLM agents
clash-prism-script
Script engine with rquickjs sandbox for Prism Engine
outrig-cli
Command-line tool for running LLM agents with podman-isolated MCP servers
nono-proxy
Network filtering proxy for the nono sandbox
henri
An agentic AI coding assistant for the terminal
tbz-airlock
Alias for tibet-zip-airlock — Sandboxed decompression with eBPF kernel enforcement
pandora_box
Syd's log inspector & profile writer
ferroday-cage-cli
Run a command inside an unprivileged Linux sandbox from a shell prompt: fresh namespaces, a provided root filesystem, seccomp and Landlock hardening, and a clean environment. Installs the fcage binary
fuellite
Fuel and byte-budget primitives: mechanical termination and output bounds. One shared budget across all composition, so fractal recursion terminates by construction.
vvva_cli
3va — secure-by-default JavaScript/TypeScript runtime built on V8 with post-quantum crypto and capability-based sandboxing
uira-security
Platform-native sandboxing (macOS/Linux) and permission management for Uira
synaptic-e2b
E2B code execution sandbox for Synaptic
sono
Sandbox for your agents
Try searching with DuckDuckGo.