agent-sandbox
rootless container sandbox that starts in 3.5 ms.
A fast, rootless sandbox and virtual resource runtime for any workload, including untrusted and AI-generated code. One 1.52 MB static binary, no daemon, 0 RAM at rest.
One binary that manages resources, of which isolation is the first. That is why there is no single row for kern in a comparison table: it is a container runtime, a sandbox, a resource slicer and a stack runner at once, in 1.52 MB with no daemon.
Secure code execution for AI applications.
run executes untrusted JavaScript and type-stripped TypeScript in a hardened QuickJS sandbox. Guest code can access only the host functions you provide.
Related contents:
Local-First AI Agent Workspace.
A local-first Agent workspace built for real work. Maka inspects projects, runs tools under a sandbox boundary, and records model messages and tool calls as recoverable execution facts — on your machine, through one Runtime Host.
Docker Sandboxes template + kit: an IaC (Pulumi/Terraform/OpenTofu + AWS/Azure/GCP CLIs) Claude Code workstation with APM baked into the agent home.
Related contents:
Sandboxes for every agent.
The micro-VM for AI agents — light enough to embed on your laptop, elastic enough to power an agentic cloud. A Box is a hardware-isolated micro-VM that runs any OCI image — and it persists. Agents install packages, write files, and resume across turns, never from cold.
Sandbox for AI Agents — Kernel-Level Isolation.
Run AI agents in a zero latency sandbox in seconds and with zero setup — Claude Code, Codex, Pi, CoPilot, Hermes, OpenCode, OpenClaw and more — nono gets you up and running within seconds, with no daemon, no container, no VM, and no disk space usage. Out of the box, nono enforces a least-privilege sandbox and supports macOS, Linux, and Windows (WSL2).
Computers for developers and agents
Durable Sandboxes that are fast, secure, and sharable.
Related contents:
Give the agent a cage, not your keys.
Give the agent a cage, not your keys. One-command Docker sandbox for AI coding agents: full autonomous permissions, per-project isolation, your host stays untouched.
The open agent runtime.
Open, self-hostable agentic runtime for organizations — durable, replayable agent sessions, human approvals, governed credentials and memory, running in managed sandboxes or on your own hardware. Apache-2.0.
Agent Substrate is a system built on top of Kubernetes which manages agent-like workloads to achieve higher scale and efficiency than Kubernetes alone can offer, with lower latency. It builds on top of Kubernetes features like Pods and Pod autoscaling, but takes the Kubernetes control-plane out of the critical path to achieve lower latency.
Related contents:
Give a coding agent its own disposable Linux machine, not yours. Disposable, network-restricted Linux VMs for AI coding agents.
clawk is a third option. cd into a repo, type clawk, and Claude Code (or Codex, or a shell) is working inside a disposable Linux VM (your code mounted in, root in the guest, no permission prompts) while your files, your keychain, and the rest of your machine stay out of reach. The agent gets its own machine instead of yours.
Empowering your AI Agents. Instant, Concurrent, Secure & Lightweight Sandbox Service for AI Agents.
Cube Sandbox is a high-performance, out-of-the-box secure sandbox service built on RustVMM and KVM. It supports both single-node deployment and easy scaling to multi-node clusters. It is compatible with the E2B SDK and can create a hardware-isolated, fully serviceable sandbox in under 60ms with less than 5MB of memory overhead.
Go full --yolo. We've got you.
macOS-native sandboxing for local agents. Move fast, break nothing. Sandbox your local AI agents so they can read/write only what they need
Related contents:
Ship and run software with isolation by default.
Tool to build & run portable, lightweight, self-contained virtual machines.
Related contents:
agent-sandbox enables easy management of isolated, stateful, singleton workloads, ideal for use cases like AI agent runtimes.
Related contents: