Re-exports @mastra/local-sandbox; auto rule (Linux+bwrap).
Compile MCP tool manifests into sandbox policies (bwrap, egress rules, and more).
Sandboxed read-only bash for Pi agents via bwrap
Sandbox npm/pnpm/yarn/bun install with bwrap (Linux) or Docker (macOS) to keep secrets in the working directory and host $HOME out of reach of postinstall scripts.
OS-isolated sandbox runtime for coding agents
OpenCode plugin that sandboxes agent commands using @anthropic-ai/sandbox-runtime (seatbelt on macOS, bubblewrap on Linux)
Cutie KOL agent component for Zylos / COCO runtime — Claude / Codex CLI under SRT sandbox
Cawdex — terminal coding agents with a mind for the whole repo. Speaks any OpenAI-compatible API with repo-aware context, benchmark tracing, MemPalace memory, and terminal-first agent workflows.
Terminal AI coding CLI. Speaks any OpenAI-compatible API (OpenRouter, OpenAI, NVIDIA, Ollama, LM Studio, DeepSeek). Modes, slash commands, multi-agent swarming, key-rotation pool, optional voice + screen-reader, sandbox + permission gates, persistent inpu
A beautiful web UI for Claude Code
Cawdex — terminal coding agents with a mind for the whole repo. Speaks any OpenAI-compatible API with repo-aware context, benchmark tracing, MemPalace memory, and terminal-first agent workflows.
Pane-embeddable coding agent. Ships direct/local/vercel-sandbox execution modes behind one interface.
Agent wrapper CLI (Go implementation)
Repo-local AI reasoning framework and agent control plane for enterprise environments
Local sandbox provider for Agentick — OS-level process isolation via macOS seatbelt and Linux bubblewrap
Multi-agent orchestration for Junction41 — supports 22 LLM providers, 12 executor frameworks, workspace/connect, and on-chain VDXF identity
Shared-memory IPC runtime for Node.js, Deno, and Bun.
My sandbox for the shitty coding agent.
An open-source, model-agnostic AI coding agent CLI — works with any LLM provider
A lightweight OS-level guard for Pi: agents stay useful, sensitive paths stay blocked, and writes stay inside the workspace you allow. No container overhead. No workflow drama.
Unified CLI for running AI coding agents with multiple model providers and sandbox options
Native permission and sandbox extension for pi.
OS + app sandboxing extension for the pi coding agent
OS-level sandbox for pi using @anthropic-ai/sandbox-runtime, with an in-pi configure wizard, shift+tab toggle, and longest-prefix project configs.
A fast, lightweight, embedded systems-friendly library for wrapping text.
Bundles the bubblewrap (bwrap) sandbox binary for bux — Linux-only process isolation
Sandbox for AI coding agents (bubblewrap on Linux, sandbox-exec on macOS)
Sandbox any command with file, network, and credential controls.
Cross-platform AI tool sandbox security implementation
Capability-aware sandbox layer for Koda — kernel-enforced FS/net/exec policies (refs #934)
Chrome DevTools Protocol (CDP) browser plugin for Nexo agents (out-of-tree subprocess).
A minimal bubblewrap-based sandbox CLI for Linux
A tool for running coding agents in sandboxes, using bwrap and pasta.
Sandbox for your agents
Anvil: Rust ACP server with first-run setup for Codex, Ollama, and OpenRouter
Help protect against malicious build scripts