<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>sandbox</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/209/feed"/>
    <updated>2026-08-26T04:30:08+00:00</updated>
    <id>https://links.biapy.com/guest/tags/209/feed</id>
            <entry>
            <id>https://links.biapy.com/links/13665</id>
            <title type="text"><![CDATA[infrastructure-sandbox-kit]]></title>
            <link rel="alternate" href="https://github.com/dirien/infrastructure-sandbox-kit" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13665"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Docker Sandboxes template + kit: an IaC (Pulumi/Terraform/OpenTofu + AWS/Azure/GCP CLIs) Claude Code workstation with APM baked into the agent home.

Related contents:

- [YOLO Mode Is the Right Default. Your Laptop Is the Wrong Place for It. @ Pulumi Blog](https://www.pulumi.com/blog/sandboxing-coding-agents-yolo-mode/).]]>
            </summary>
            <updated>2026-08-17T09:00:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13661</id>
            <title type="text"><![CDATA[Warning: Security Risk]]></title>
            <link rel="alternate" href="https://rakazo.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13661"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open-source Grok Bot alternative. Choose your own model and sandbox.

Web, desktop, and mobile. Bring your own AI and sandbox. The product is still early (beta).

Each bot has one thread, one computer, memory, routines, and history. A bot can also spawn more bots — each a regular peer with its own thread and computer — or run short-lived subagents inside the current turn. This repository is the complete core product — it runs without a Rakazo-operated control plane.

- [Rakazo @ GitHub](https://github.com/elie222/rakazo).]]>
            </summary>
            <updated>2026-08-17T08:38:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13487</id>
            <title type="text"><![CDATA[exe.dev]]></title>
            <link rel="alternate" href="https://exe.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13487"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Computers for developers and agents

Durable Sandboxes that are fast, secure, and sharable.

Related contents:

- [\#1021: We got addicted to an AI model we can&amp;#039;t talk about @ Syntax](https://syntax.fm/show/1021/we-got-addicted-to-an-ai-model-we-can-t-talk-about).]]>
            </summary>
            <updated>2026-08-02T14:21:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13418</id>
            <title type="text"><![CDATA[Cleat]]></title>
            <link rel="alternate" href="https://cleat.sh/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13418"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Give the agent a cage, not your keys.

 Give the agent a cage, not your keys. One-command Docker sandbox for AI coding agents: full autonomous permissions, per-project isolation, your host stays untouched. 

- [Cleat @ GitHub](https://github.com/cleatdev/cleat).]]>
            </summary>
            <updated>2026-07-27T05:39:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13294</id>
            <title type="text"><![CDATA[agent-substrate/substrate: Agent Substrate: the core system]]></title>
            <link rel="alternate" href="https://github.com/agent-substrate/substrate" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13294"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Agent Substrate is a system built on top of Kubernetes which manages agent-like workloads to achieve higher scale and efficiency than Kubernetes alone can offer, with lower latency. It builds on top of Kubernetes features like Pods and Pod autoscaling, but takes the Kubernetes control-plane out of the critical path to achieve lower latency.

Related contents:

- [Why sandboxing your agent is not enough @ CNCF](https://www.cncf.io/blog/2026/07/07/why-sandboxing-your-agent-is-not-enough/).]]>
            </summary>
            <updated>2026-07-15T07:57:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13277</id>
            <title type="text"><![CDATA[Clawk]]></title>
            <link rel="alternate" href="https://github.com/clawkwork/clawk" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13277"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Give a coding agent its own disposable Linux machine, not yours.  Disposable, network-restricted Linux VMs for AI coding agents.

clawk is a third option. cd into a repo, type clawk, and Claude Code (or Codex, or a shell) is working inside a disposable Linux VM (your code mounted in, root in the guest, no permission prompts) while your files, your keychain, and the rest of your machine stay out of reach. The agent gets its own machine instead of yours.]]>
            </summary>
            <updated>2026-07-15T06:34:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13196</id>
            <title type="text"><![CDATA[Kyushu]]></title>
            <link rel="alternate" href="https://kyushu.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13196"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Self-Hostable Wasm Sandbox for JavaScript Workers

Ever wanted to run a Cloudflare Workers-style handler, on a VPS or anywhere, without Node.js, Bun, or even Docker?

Kyushu is an open source CLI that lets you write a JavaScript or TypeScript handler, build it into a self-contained WebAssembly binary, and run it anywhere with one command - kyu.

- [Kyushu @ GitHub](https://github.com/peterpeterparker/kyushu).]]>
            </summary>
            <updated>2026-07-03T08:48:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13177</id>
            <title type="text"><![CDATA[Anthropic Sandbox Runtime (srt)]]></title>
            <link rel="alternate" href="https://github.com/anthropic-experimental/sandbox-runtime" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13177"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container. 

Related contents:

- [Sandboxing an AI Agent @ Sajal Sharma](https://sajalsharma.com/posts/sandboxing-an-ai-agent/).]]>
            </summary>
            <updated>2026-07-02T12:08:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13152</id>
            <title type="text"><![CDATA[⚡ Godcoder]]></title>
            <link rel="alternate" href="https://github.com/eli-labz/Godcoder" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13152"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Godcoder doesn&amp;#039;t just use a harness. It writes one, improves it, and optimizes it — autonomously, in real time.

 A local-first, open-source coding agent for your desktop. Bring your own LLM key; your code stays on your machine and only ever leaves to the model provider. The AI Agent builds its own Harness.]]>
            </summary>
            <updated>2026-06-29T10:48:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13067</id>
            <title type="text"><![CDATA[iii]]></title>
            <link rel="alternate" href="https://iii.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13067"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Three primitives. Zero integration cost.
 
 Effortlessly compose, extend, and observe every service in real-time for the first time ever. 
iii is the easiest way to compose, extend, and observe every service in your stack in real time.

Every backend starts as a project before the first line of business logic. Queues, cron, HTTP, state, observability, agents, and sandboxes each usually bring their own integration story. iii collapses that into one live system surface.

- [iii @ GitHub](https://github.com/iii-hq/iii).]]>
            </summary>
            <updated>2026-06-19T12:58:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13000</id>
            <title type="text"><![CDATA[SafeAgentDB]]></title>
            <link rel="alternate" href="https://github.com/Aidan945/SafeAgentDB" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13000"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Isolated databases for every AI agent branch. Build, test, and migrate in parallel. Production stays untouched. 

Database safety infrastructure for AFK agentic development.

SafeAgentDB is built for serious vibe coders shipping real products with a team — whether your teammates are people, AI agents, or both. Once you have many branches in flight at the same time, one shared database becomes the thing everyone breaks. SafeAgentDB gives every branch and PR a live preview URL backed by its own isolated database, so agents can run migrations, hydrate realistic data, and test real app behavior without risking production, corrupting shared development data, or stepping on each other.

Built first for Supabase + Vercel + GitHub Actions, with guidance for adapting the same infrastructure pattern to other stacks.]]>
            </summary>
            <updated>2026-06-11T13:33:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12918</id>
            <title type="text"><![CDATA[sandboxd]]></title>
            <link rel="alternate" href="https://github.com/tastyeffectco/sandboxd" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12918"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Self-hosted dev sandboxes with preview URLs. One command. No Kubernetes, perfect for coding agents and Saas factories.

The open-source engine for AI app-builder products.
Give every user an isolated cloud dev environment, a built-in coding agent, and a live preview URL — self-hosted, on one machine, in one command.]]>
            </summary>
            <updated>2026-06-08T05:20:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12899</id>
            <title type="text"><![CDATA[Sandcastle]]></title>
            <link rel="alternate" href="https://github.com/mattpocock/sandcastle" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12899"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Orchestrate sandboxed coding agents in TypeScript with sandcastle.run().

A TypeScript library for orchestrating AI coding agents in isolated sandboxes.]]>
            </summary>
            <updated>2026-06-02T11:30:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12860</id>
            <title type="text"><![CDATA[vmexec]]></title>
            <link rel="alternate" href="https://gitlab.archlinux.org/archlinux/vmexec" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12860"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Run a single command in a speedy virtual machine with zero-setup
vmexec is a zero-setup CLI tool that runs single commands in a throwaway virtual machines.
The idea is for you to run a command in VM without having think about the performance implications, how to mount files, how to forward ports, etc.
Nowadays, many are used to the convenience of container runners such as podman or docker but so far it hasn&amp;#039;t been as covenient to run a VM, often requiring a manual set up step.

Related contents:

- [Your Container Is Not a Sandbox @ Emir Beganović](https://emirb.github.io/blog/microvm-2026/).]]>
            </summary>
            <updated>2026-05-28T09:44:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12858</id>
            <title type="text"><![CDATA[microsandbox]]></title>
            <link rel="alternate" href="https://microsandbox.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12858"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Every agent deserves its own machine.

Run agents in secure, local-first sandboxes. On your laptop, in your VPC, on-prem, or in our cloud. Programmable, fast, and yours.

microsandbox takes a different approach: every sandbox is a real VM with its own Linux kernel. It provides security primitives for preventing exploits like secret exfiltration. And it runs locally on your machine.

- [microsandbox documentation](https://docs.microsandbox.dev/getting-started/introduction).
- [microsandbox @ GitHub](https://github.com/superradcompany/microsandbox).

Related contents:

- [Your Container Is Not a Sandbox @ Emir Beganović](https://emirb.github.io/blog/microvm-2026/).]]>
            </summary>
            <updated>2026-05-28T09:39:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12814</id>
            <title type="text"><![CDATA[Sandbox Agent SDK]]></title>
            <link rel="alternate" href="https://sandboxagent.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12814"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

- [Sandbox Agent SDK @ GitHub](https://github.com/rivet-dev/sandbox-agent).

Related contents:

- [We Reverse-Engineered Docker Sandbox&amp;#039;s Undocumented MicroVM API @ Rivet](https://rivet.dev/blog/2026-02-04-we-reverse-engineered-docker-sandbox-undocumented-microvm-api/).]]>
            </summary>
            <updated>2026-05-22T16:09:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12776</id>
            <title type="text"><![CDATA[Superserve]]></title>
            <link rel="alternate" href="https://www.superserve.ai/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12776"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Persistent &amp;amp; Secure sandboxes for AI agents.

Give your agents lightning-fast sandboxes with persistent state and versioned filesystems.

- [Superserve @ GitHub](https://github.com/superserve-ai/superserve).]]>
            </summary>
            <updated>2026-05-15T15:14:12+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12700</id>
            <title type="text"><![CDATA[context-mode]]></title>
            <link rel="alternate" href="https://context-mode.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12700"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Save 98% of your AI coding agent&amp;#039;s context window.

 Context window optimization for AI coding agents. Sandboxes tool output, 98% reduction. 15 platforms 

- [context-mode @ GitHub](https://github.com/mksglu/context-mode).]]>
            </summary>
            <updated>2026-05-14T10:41:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12636</id>
            <title type="text"><![CDATA[smolvm]]></title>
            <link rel="alternate" href="https://smolmachines.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12636"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Ship and run software with isolation by default.

 Tool to build &amp;amp; run portable, lightweight, self-contained virtual machines. 

- [smolvm @ GitHub](https://github.com/smol-machines/smolvm).

Related contents:

- [smolvm - Des microVMs qui se lancent en moins de 200ms @ Korben :fr:](https://korben.info/smolvm-microvm-portable-rust.html).]]>
            </summary>
            <updated>2026-04-28T08:51:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12630</id>
            <title type="text"><![CDATA[E2B]]></title>
            <link rel="alternate" href="https://e2b.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12630"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Enterprise AI Agent Cloud. 

AI Sandboxes for Open-source, secure environment with real-world tools for enterprise-grade agents.
 
- [E2B @ GitHub](https://github.com/e2b-dev/E2B).

Related contents:

- [What every dev should know about AI sandboxes @ Engineer&amp;#039;s Codex](https://read.engineerscodex.com/p/every-dev-should-know-about-ai-sandboxes).
- [Your Container Is Not a Sandbox @ Emir Beganović](https://emirb.github.io/blog/microvm-2026/).]]>
            </summary>
            <updated>2026-05-28T09:37:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12461</id>
            <title type="text"><![CDATA[Hazmat]]></title>
            <link rel="alternate" href="https://github.com/dredozubov/hazmat" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12461"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Full autonomy. Controlled environment.
OS-level containment for AI coding agents on macOS.

 macOS containment for AI agents — user isolation, kernel sandbox, pf firewall, DNS blocklist, backup/rollback. TLA+ verified.

AI coding agents are most useful when you let them work autonomously. But full autonomy means the agent runs with your full privileges, your credentials, your files.

Hazmat makes that safe.

Related contents:

- [Hazmat - Vos agents IA en cage sous macOS @ Korben :fr:](https://korben.info/hazmat-sandbox-macos-agents-ia.html).]]>
            </summary>
            <updated>2026-04-13T09:17:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12400</id>
            <title type="text"><![CDATA[🫙 Zerobox]]></title>
            <link rel="alternate" href="https://github.com/afshinm/zerobox" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12400"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sandbox any command with file, network, and credential controls.

 Lightweight, cross-platform process sandboxing powered by OpenAI Codex&amp;#039;s runtime. Sandbox any command with file, network, and credential controls.]]>
            </summary>
            <updated>2026-04-03T14:26:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12377</id>
            <title type="text"><![CDATA[jai]]></title>
            <link rel="alternate" href="https://jai.scs.stanford.edu/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12377"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Go hard on agents, not on your filesystem.
easy containment for AI agents.

Use jai for effortless containment of AI agents on Linux.
jai strives to be the easiest container in the world to configure--so easy that you never again need to run a code assistant without protection. It&amp;#039;s not a substitute for docker or podman when you need better isolation. But if you regularly do risky things like run an AI CLI with your own privileges in your home directory on a computer that you care about, then jai could reduce the damage when things go wrong.

- [jai @ GitHub](https://github.com/stanford-scs/jai).]]>
            </summary>
            <updated>2026-03-30T18:50:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12245</id>
            <title type="text"><![CDATA[Agent Sandbox]]></title>
            <link rel="alternate" href="https://agent-sandbox.sigs.k8s.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12245"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[agent-sandbox enables easy management of isolated, stateful, singleton workloads, ideal for use cases like AI agent runtimes. 

- [Agent Sandbox @ GitHub](https://github.com/kubernetes-sigs/agent-sandbox).

Related contents:

- [Running Agents on Kubernetes with Agent Sandbox @ Kubernetes blog](https://kubernetes.io/blog/2026/03/20/running-agents-on-kubernetes-with-agent-sandbox/).
- [Why sandboxing your agent is not enough @ CNCF](https://www.cncf.io/blog/2026/07/07/why-sandboxing-your-agent-is-not-enough/).]]>
            </summary>
            <updated>2026-07-15T07:56:22+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12216</id>
            <title type="text"><![CDATA[NVIDIA OpenShell]]></title>
            <link rel="alternate" href="https://docs.nvidia.com/openshell/latest/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12216"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OpenShell is the safe, private runtime for autonomous AI agents. 

NVIDIA OpenShell is the safe, private runtime for autonomous AI agents. It provides sandboxed execution environments that protect your data, credentials, and infrastructure. Agents run with exactly the permissions they need and nothing more, governed by declarative policies that prevent unauthorized file access, data exfiltration, and uncontrolled network activity.

- [NVIDIA OpenShell @ GitHub](https://github.com/NVIDIA/OpenShell).

Related contents:

- [NVIDIA OpenShell Secures the Agent. Who Governs the Fleet? @ Tigera](https://www.tigera.io/blog/nvidia-openshell-secures-the-agent-who-governs-the-fleet/).]]>
            </summary>
            <updated>2026-07-20T09:24:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12185</id>
            <title type="text"><![CDATA[Bromure]]></title>
            <link rel="alternate" href="https://github.com/rderaison/bromure" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12185"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Secure, ephemeral browsing in a disposable VM (macOS only).

Bromure is a native macOS app that runs every browser session inside a lightweight, disposable Linux virtual machine using Apple&amp;#039;s Virtualization.framework. The browser and your Mac don&amp;#039;t share an operating system, a filesystem, or even a kernel. When you close the window, the VM is destroyed -- cookies, history, malware, trackers, all of it. Gone.]]>
            </summary>
            <updated>2026-03-19T14:32:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12104</id>
            <title type="text"><![CDATA[OneCLI]]></title>
            <link rel="alternate" href="https://onecli.sh/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12104"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Give your agents access, not your secrets.
The open-source secret vault for AI agents.
 Store once. Inject anywhere. Agents never see the keys. 

Open-source credential vault. Your agents call services and never see a key.

OneCLI is an open-source gateway that sits between your AI agents and the services they call. Instead of baking API keys into every agent, you store credentials once in OneCLI and the gateway injects them transparently. Agents never see the secrets.

- [OneCLI @ GitHub](https://github.com/onecli/onecli).]]>
            </summary>
            <updated>2026-07-24T12:29:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12062</id>
            <title type="text"><![CDATA[yolobox]]></title>
            <link rel="alternate" href="https://github.com/finbarr/yolobox" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12062"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Let your AI go full send. Your home directory stays home.

Run Claude Code, Codex, or any AI coding agent in &amp;quot;yolo mode&amp;quot; without nuking your home directory.

Related contents:

- [Yolobox - Lâchez vos agents IA sauvages sans flinguer votre home @ Korben :fr:](https://korben.info/yolobox-sandbox-ia-agents.html).]]>
            </summary>
            <updated>2026-03-09T09:55:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12007</id>
            <title type="text"><![CDATA[OpenSandbox]]></title>
            <link rel="alternate" href="https://open-sandbox.ai/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12007"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Universal Sandbox Infrastructure for AI Applications.

Securely run commands, filesystems, code interpreters, browsers, and developer tools in isolated runtime environments.

 OpenSandbox is a general-purpose sandbox platform for AI applications, offering multi-language SDKs, unified sandbox APIs, and Docker/Kubernetes runtimes for scenarios like Coding Agents, GUI Agents, Agent Evaluation, AI Code Execution, and RL Training. 

- [OpenSandbox @ GitHub](https://github.com/alibaba/OpenSandbox).]]>
            </summary>
            <updated>2026-03-04T12:33:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11967</id>
            <title type="text"><![CDATA[just-bash]]></title>
            <link rel="alternate" href="https://justbash.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11967"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A sandboxed bash interpreter for AI agents. Pure TypeScript with in-memory filesystem.

A simulated bash environment with an in-memory virtual filesystem, written in TypeScript.
Designed for AI agents that need a secure, sandboxed bash environment.
Supports optional network access via curl with secure-by-default URL filtering.

- [just-bash @ GitHub](https://github.com/vercel-labs/just-bash).]]>
            </summary>
            <updated>2026-03-02T06:46:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11798</id>
            <title type="text"><![CDATA[LiteBox]]></title>
            <link rel="alternate" href="https://github.com/microsoft/litebox" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11798"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A security-focused library OS supporting kernel- and user-mode execution.

LiteBox is a sandboxing library OS that drastically cuts down the interface to the host, thereby reducing attack surface. It focuses on easy interop of various &amp;quot;North&amp;quot; shims and &amp;quot;South&amp;quot; platforms. LiteBox is designed for usage in both kernel and non-kernel scenarios.]]>
            </summary>
            <updated>2026-02-13T10:54:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11764</id>
            <title type="text"><![CDATA[Matchlock]]></title>
            <link rel="alternate" href="https://github.com/jingkaihe/matchlock" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11764"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Matchlock secures AI agent workloads with a Linux-based sandbox. 

Matchlock is a CLI tool for running AI agents in ephemeral microVMs - with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Your secrets never enter the VM.]]>
            </summary>
            <updated>2026-02-09T13:08:00+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11751</id>
            <title type="text"><![CDATA[Vibe]]></title>
            <link rel="alternate" href="https://github.com/lynaghk/vibe" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11751"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Easy Linux virtual machine on MacOS to sandbox LLM agents.

Vibe is a quick, zero-configuration way to spin up a Linux virtual machine on Mac to sandbox LLM agents.

Related contents:

- [Vos agents IA sécurisés en -10 sec. sur Mac @ Korben :fr:](https://korben.info/vibe-coding-terminal-llm.html).]]>
            </summary>
            <updated>2026-02-09T08:49:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11628</id>
            <title type="text"><![CDATA[Vagrant]]></title>
            <link rel="alternate" href="https://developer.hashicorp.com/vagrant" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11628"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Vagrant is the command line utility for managing the lifecycle of virtual machines. Isolate dependencies and their configuration within a single disposable and consistent environment.

- [Vagrant @ GitHub](https://github.com/hashicorp/vagrant).

Related contents:

- [Running Claude Code dangerously (safely) @ Emil Burzo](https://blog.emilburzo.com/2026/01/running-claude-code-dangerously-safely/).
- [Maitrisez Vagrant pour vos environnements @ DevSecOps :fr:](https://blog.stephane-robert.info/docs/infra-as-code/provisionnement/vagrant/).
- [On Ditching Vagrant @ https://benjamintoll.com/](https://benjamintoll.com/2026/06/29/on-ditching-vagrant/).]]>
            </summary>
            <updated>2026-07-23T06:16:23+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11616</id>
            <title type="text"><![CDATA[Fence]]></title>
            <link rel="alternate" href="https://github.com/Use-Tusk/fence" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11616"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Lightweight, container-free sandbox for running commands with network and filesystem restrictions.

Fence wraps commands in a sandbox that blocks network access by default and restricts filesystem operations based on configurable rules. It&amp;#039;s most useful for running semi-trusted code (package installs, build scripts, CI jobs, unfamiliar repos) with controlled side effects, and it can also complement AI coding agents as defense-in-depth.]]>
            </summary>
            <updated>2026-01-26T12:59:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11522</id>
            <title type="text"><![CDATA[Leash]]></title>
            <link rel="alternate" href="https://leash.strongdm.ai/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11522"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security, visibility, and authorization for AI agents

Leash wraps AI coding agents in containers and monitors their activity. You define policies in Cedar; Leash enforces them instantly.

Authorize and monitor your AI agents with policy enforcement, sandboxed execution, and real-time observability—ensuring they operate safely within your defined boundaries.

- [Leash @ GitHub](https://github.com/strongdm/leash).]]>
            </summary>
            <updated>2026-01-19T06:51:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10758</id>
            <title type="text"><![CDATA[Katakate (K7)]]></title>
            <link rel="alternate" href="https://katakate.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10758"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Create and manage micro VMs at scale for safe execution of untrusted code.
Secure sandboxed compute for AI agents and workloads

 K7 Demo

Katakate aims to make it easy to create, manage and orchestrate lightweight safe VM sandboxes for executing untrusted code, at scale. It is built on battle-tested VM isolation with Kata, Firecracker and Kubernetes. It is orignally motivated by AI agents that need to run arbitrary code at scale.

- [Katakate @ GitHub](https://github.com/Katakate/k7).
- [Katakate documentation](https://docs.katakate.org/).]]>
            </summary>
            <updated>2025-10-22T11:39:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10754</id>
            <title type="text"><![CDATA[NixPak]]></title>
            <link rel="alternate" href="https://github.com/nixpak/nixpak" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10754"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sandboxing for Nix.

NixPak is essentially a fancy declarative wrapper around bwrap. You can use it to sandbox all sorts of Nix-packaged applications, including graphical ones.]]>
            </summary>
            <updated>2025-10-21T19:03:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10568</id>
            <title type="text"><![CDATA[microbox]]></title>
            <link rel="alternate" href="https://github.com/HQarroum/microbox" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10568"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[📦 Lightweight, ephemeral, sandboxes for Linux.

Create lightweight sandboxes for Linux with host isolation, rootfs images, and networking.

Microbox is a sandbox runtime that creates ephemeral and isolated execution environments on Linux by combining specific kernel features such as namespaces, cgroups, seccomp, and capabilities. It provides lightweight sandboxes to run container-like applications securely.]]>
            </summary>
            <updated>2025-10-07T06:29:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/83</id>
            <title type="text"><![CDATA[CodeRunner]]></title>
            <link rel="alternate" href="https://github.com/instavm/coderunner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/83"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Run AI Generated Code Locally.
A secure local sandbox to run LLM-generated code using Apple containers.

CodeRunner is an MCP (Model Context Protocol) server that executes AI-generated code in a sandboxed environment on your Mac using Apple&amp;#039;s native containers.

Related contents:

- [I Want Everything Local — Building My Offline AI Workspace @ InstaVM](https://instavm.io/blog/building-my-offline-ai-workspace).
- [Accelerate developer productivity with these 9 open source AI and MCP projects @ GitHub blog](https://github.blog/open-source/accelerate-developer-productivity-with-these-9-open-source-ai-and-mcp-projects/).]]>
            </summary>
            <updated>2025-10-27T14:06:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1159</id>
            <title type="text"><![CDATA[Hyperlight]]></title>
            <link rel="alternate" href="https://github.com/hyperlight-dev/hyperlight" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1159"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Hyperlight is a lightweight Virtual Machine Manager (VMM) designed to be embedded within applications. It enables safe execution of untrusted code within micro virtual machines with very low latency and minimal overhead.]]>
            </summary>
            <updated>2025-08-28T19:08:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1234</id>
            <title type="text"><![CDATA[TinyKVM]]></title>
            <link rel="alternate" href="https://github.com/varnish/tinykvm" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1234"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[VMM for native-performance sandboxing.

TinyKVM is a simple, slim and specialized userspace emulator library with native performance.

TinyKVM is designed to execute regular Linux programs and also excels at request-based workloads in high-performance HTTP caches and web servers.

Related contents:

- [TinyKVM: The Fastest Sandbox @ Varnish Software blog](https://info.varnish-software.com/blog/tinykvm-the-fastest-sandbox).]]>
            </summary>
            <updated>2025-08-28T19:23:00+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3423</id>
            <title type="text"><![CDATA[Cuckoo3]]></title>
            <link rel="alternate" href="https://cuckoo-hatch.cert.ee/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3423"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Malware analysis tool.
Cuckoo3 is a Python 3 open source automated malware analysis system. 

Cuckoo3 is an open-source tool to test suspicious files or links in a controlled environment.
It will test them in a sandboxed platform emulator(s) and generate a report, showing what the files or websites did during the test.

- [Cuckoo3 @ GitHub](https://github.com/cert-ee/cuckoo3).]]>
            </summary>
            <updated>2025-08-29T01:27:01+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3477</id>
            <title type="text"><![CDATA[Postgres Sandbox]]></title>
            <link rel="alternate" href="https://postgres.new/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3477"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[In-browser Postgres sandbox with AI assistance.

With postgres.new, you can instantly spin up an unlimited number of Postgres databases that run directly in your browser (and soon, deploy them to S3).

- [postgres.new @ GitHub](https://github.com/supabase-community/postgres-new).]]>
            </summary>
            <updated>2025-08-29T01:37:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4455</id>
            <title type="text"><![CDATA[Daytona]]></title>
            <link rel="alternate" href="https://www.daytona.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4455"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Dev Environment Management Platform. The future of dev environments.

Daytona is the enterprise-grade Codespaces alternative for managing self-hosted, secure and standardized development environments. 

- [Daytona @ GitHub](https://github.com/daytonaio/daytona).

Related contents:

- [What every dev should know about AI sandboxes @ Engineer&amp;#039;s Codex](https://read.engineerscodex.com/p/every-dev-should-know-about-ai-sandboxes).
- [Sandboxing an AI Agent @ Sajal Sharma](https://sajalsharma.com/posts/sandboxing-an-ai-agent/).]]>
            </summary>
            <updated>2026-07-02T12:09:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4783</id>
            <title type="text"><![CDATA[werf]]></title>
            <link rel="alternate" href="https://werf.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4783"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Efficient and consistent CI/CD with Kubernetes.

A solution for implementing efficient and consistent software delivery to Kubernetes facilitating best practices.
werf is a CNCF Sandbox CLI tool to implement full-cycle CI/CD to Kubernetes easily. werf integrates into your CI system and leverages familiar and reliable technologies, such as Git, Dockerfile, Helm, and Buildah.

- [werf @ GitHub](https://github.com/werf/werf).]]>
            </summary>
            <updated>2025-08-29T05:15:00+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4817</id>
            <title type="text"><![CDATA[Try It Online]]></title>
            <link rel="alternate" href="https://tio.run/#" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4817"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[TIO is a family of online interpreters for an evergrowing list of practical and recreational programming languages.
To use TIO, simply click the arrow below, pick a programming language, and start typing. Once you click the run button, your code is sent to a TIO arena, executed in a sandboxed environment, and the results are sent back to your browser. You can share your code by generating a client-side permalink that encodes code and input directly in the URL.

- [TIO – Des interpréteurs de code gratuits pour les développeurs et les enseignants @ Korben (fr)](https://korben.info/tio-des-interpreteurs-de-code-gratuits-pour-les-developpeurs-et-les-enseignants.html).]]>
            </summary>
            <updated>2025-08-29T05:20:01+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4887</id>
            <title type="text"><![CDATA[VAmPI]]></title>
            <link rel="alternate" href="https://github.com/erev0s/VAmPI" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4887"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Vulnerable REST API with OWASP top 10 vulnerabilities for security testing.

VAmPI is a vulnerable API made with Flask and it includes vulnerabilities from the OWASP top 10 vulnerabilities for APIs. It was created as I wanted a vulnerable API to evaluate the efficiency of tools used to detect security issues in APIs. It includes a switch on/off to allow the API to be vulnerable or not while testing. This allows to cover better the cases for false positives/negatives. VAmPI can also be used for learning/teaching purposes. You can find a bit more details about the vulnerabilities in erev0s.com.]]>
            </summary>
            <updated>2025-08-29T05:31:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5595</id>
            <title type="text"><![CDATA[Sandpack]]></title>
            <link rel="alternate" href="https://sandpack.codesandbox.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5595"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Component toolkit for creating live-running code editing experiences.

Sandpack is a component toolkit for creating your own live running code editing experience powered by CodeSandbox.

- [Sandpack @ GitHub](https://github.com/codesandbox/sandpack).]]>
            </summary>
            <updated>2026-08-05T09:54:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5963</id>
            <title type="text"><![CDATA[PHPSandbox]]></title>
            <link rel="alternate" href="https://play.phpsandbox.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5963"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[PHPSandbox + Packagist.
This is a playground to try Composer packages. With it, you can try 350k+ packages using a standard PHP v8.1 environment.]]>
            </summary>
            <updated>2025-08-29T08:30:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6375</id>
            <title type="text"><![CDATA[Eleven]]></title>
            <link rel="alternate" href="https://github.com/eleven-sh/cli" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6375"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A CLI to create code sandboxes with automatic HTTPS and long running processes in your cloud provider account.]]>
            </summary>
            <updated>2025-08-29T09:39:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6708</id>
            <title type="text"><![CDATA[vm2]]></title>
            <link rel="alternate" href="https://github.com/patriksimek/vm2" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6708"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Advanced vm/sandbox for Node.js.
vm2 is a sandbox that can run untrusted code with whitelisted Node&amp;#039;s built-in modules. Securely!]]>
            </summary>
            <updated>2025-08-29T10:34:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/8227</id>
            <title type="text"><![CDATA[Automated Malware Analysis - Cuckoo Sandbox]]></title>
            <link rel="alternate" href="http://cuckoosandbox.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/8227"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Malware? Tear it apart, discover its ins and outs and collect actionable threat data. Cuckoo is the leading open source automated malware analysis system.]]>
            </summary>
            <updated>2025-08-29T14:49:07+00:00</updated>
        </entry>
    </feed>
