Agent Code Sandboxing AI Agents

Tools and platforms for isolating, containerizing, and safely executing untrusted code from AI agents using Docker, VMs, WebSockets, or namespace-based sandboxes. Does NOT include general container orchestration, deployment platforms, or security monitoring without execution isolation capabilities.

There are 113 agent code sandboxing agents tracked. 3 score above 70 (verified tier). The highest-rated is e2b-dev/E2B at 92/100 with 11,263 stars and 3,818,023 monthly downloads. 9 of the top 10 are actively maintained.

Get all 113 projects as JSON

curl "https://pt-edge.onrender.com/api/v1/datasets/quality?domain=agents&subcategory=agent-code-sandboxing&limit=20"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.

# Agent Score Tier
1 e2b-dev/E2B

Open-source, secure environment with real-world tools for enterprise-grade agents.

92
Verified
2 alibaba/OpenSandbox

OpenSandbox is a general-purpose sandbox platform for AI applications,...

87
Verified
3 e2b-dev/infra

Infrastructure that's powering E2B Cloud.

76
Verified
4 boxlite-ai/boxlite

Sandboxes for every agent. Embeddable, stateful, snapshots, and hardware isolation.

64
Established
5 always-further/nono

Secure, kernel-enforced sandbox CLI and SDKs for AI agents. Capability-based...

63
Established
6 eugene1g/agent-safehouse

Sandbox your local AI agents so they can read/write only what they need

59
Established
7 zerobootdev/zeroboot

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

57
Established
8 multikernel/sandlock

Lightweight process-based sandbox for Linux, no container, no VM, no root.

57
Established
9 agbcloud/agbcloud-sdk

AI-native cross-platform sandboxes for developers, featuring multimodal...

54
Established
10 adammiribyan/zeroboot

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

54
Established
11 HACKE-RC/Bandsox

Sanboxes for AI agents and humans

53
Established
12 angelorc/vmsan

Firecracker made simple. Spin up secure microVMs in milliseconds, from...

53
Established
13 dtormoen/tsk-tsk

Keeping your agents out of trouble with sandboxed coding agent automation

51
Established
14 tomascupr/sandstorm

Run Claude agents in secure cloud sandboxes — via API, CLI, or Slack. One...

50
Established
15 mavdol/capsule

A secure, durable runtime to sandbox AI agent tasks. Run untrusted code in...

47
Emerging
16 Th0rgal/sandboxed.sh

Self-hosted orchestrator for AI autonomous agents. Run Claude Code & Open...

45
Emerging
17 runtm-ai/runtm

Open-source sandboxes where coding agents build and deploy. Spin up isolated...

45
Emerging
18 adarsh9780/safe-py-runner

A lightweight, secure-by-default Python code runner designed for LLM agents.

43
Emerging
19 projecteru2/cocoon

Lightweight MicroVM VMM built on Cloud Hypervisor for AI

42
Emerging
20 EXboys/skilllite

A lightweight secure Self-evolution engine built in Rust, featuring a...

41
Emerging
21 railroad-dev/railroad

Run Claude Code at full speed, safely. OS-level command blocking with no...

41
Emerging
22 rpfilomeno/opencode-docker

Stop prompt injection catastrophe! Run your AI Agents in secure isolated...

39
Emerging
23 branchbox/branchbox

Parallel, isolated dev environments for humans and AI coding agents. Real...

39
Emerging
24 Parassharmaa/agent-sandbox

A sandboxed execution environment for AI agents via WASM

39
Emerging
25 onyx-dot-app/python-sandbox

Secure and lightweight Python code execution environment for LLMs

38
Emerging
26 legionus/devkit

The project allows you to manage isolated containers with AI agents

37
Emerging
27 89luca89/clampdown

Run AI coding agents in hardened container sandboxes.

37
Emerging
28 jamesmurdza/upstream-agents

Run AI coding agents in isolated sandboxes connected to your GitHub repositories

37
Emerging
29 stacklok/brood-box

CLI tool for running coding agents inside hardware-isolated microVMs

36
Emerging
30 foundry-works/foundry-sandbox

Ephemeral, batteries-included Docker workspaces that isolate AI coding...

36
Emerging
31 rivet-dev/secure-exec

Secure Node.js Execution Without a Sandbox A lightweight library for secure...

36
Emerging
32 joshualamerton/agentic-sandbox

Simulation environment for testing and validating autonomous agents

35
Emerging
33 gizmax/Sandcastle

Production-ready AI agent workflow orchestrator. 63 integrations, EU AI Act...

35
Emerging
34 getlark/runtimeuse

Run AI agents inside sandboxes over WebSockets

34
Emerging
35 Raynan00/sandpy

Browser-native Python sandbox for AI agents

33
Emerging
36 akshayaggarwal99/boxed

The Sovereign Code Execution Engine for AI Agents. Run untrusted code safely...

33
Emerging
37 the-void-ia/void-box

Composable agent runtime with enforced isolation boundaries

33
Emerging
38 ixchio/agent-sandbox-runtime

A secure runtime for self-correcting AI agents with Docker sandboxing.

32
Emerging
39 STONE-CELL-SPF-JOSEPH-STONE/SPFsmartGATE

AI Security Gateway — Compiled Rust enforcement between AI agents and your...

32
Emerging
40 deevus/pixels

Disposable Linux containers for AI coding agents, with extensible backends

32
Emerging
41 HappyHackingSpace/sindoq

AI Sandbox

31
Emerging
42 reoring/botbox

Kubernetes sidecar that sandboxes container egress. Deny-by-default...

30
Emerging
43 Orellius/Laminae

AI personality, safety, red-teaming, and sandboxing in Rust SDK.

30
Emerging
44 AxeForging/aigate

OS-level sandbox for AI coding agents - kernel-enforced file, command, and...

27
Experimental
45 arcboxlabs/arcbox

Run AI agents on real and isolated machines — own kernel, filesystem, and...

27
Experimental
46 kajogo777/the-agent-sandbox-taxonomy

An open taxonomy and scoring framework for evaluating AI agent sandboxes: 7...

27
Experimental
47 seznam/jailoc

🔒 Jail your AI agents — sandboxed Docker environments with network isolation...

27
Experimental
48 sevorix/sevorix-lite

Sevorix Lite is a Rust-native, open-source runtime containment engine for...

27
Experimental
49 Parassharmaa/agent-fetch

Sandboxed HTTP client with SSRF protection for AI agents. Prevents DNS...

26
Experimental
50 numcys/sudomode

The Missing sudo Command for AI Agents.

26
Experimental
51 hyperterse/sandboxer

Single, consistent interface to run code, manage files, and control isolated...

26
Experimental
52 danievanzyl/pyro

Open-source Firecracker microVM sandbox platform for AI agents

25
Experimental
53 haasonsaas/capsule-run

Lightweight, secure sandboxed command execution for AI agents

25
Experimental
54 dredozubov/hazmat

macOS containment for AI agents — user isolation, kernel sandbox, pf...

24
Experimental
55 opencapsule/opencapsule

Secure Code Execution Runtime for AI Agents

24
Experimental
56 DavidKim0326/DUDA

Isolation Guardian for Claude Code — Prevent AI agents from breaking...

24
Experimental
57 qhkm/zeptocapsule

Isolation sandbox for AI agents — process, namespace, and Firecracker capsules

24
Experimental
58 c4rb0nx1/tuprwre

That install command your AI agent just ran? Never touched your host....

23
Experimental
59 nhevers/agent-sandbox

Sandboxed code execution for AI agents

23
Experimental
60 liut/strata

Lightweight Session Sandbox Service — Isolated Shell Environments via...

23
Experimental
61 sauravbhattacharya001/ai

Contract-enforced sandbox for studying AI agent self-replication safety

23
Experimental
62 0rzech/vibe-containers

Simple sandbox Podman containers for Mistral Vibe

23
Experimental
63 Mickdownunder/atlas-validation-layer

Bounded validation and sandbox layer for the Operator research control plane

23
Experimental
64 Embedded-Focus/agent-circus

Run AI coding agents in sandboxed containers communicate via ACP

23
Experimental
65 KometzRobot/capsule-spec

Open tools for AI identity persistence — Capsule Spec, Loop Harness, Cinder Enhanced

23
Experimental
66 heromen22/sandstorm

🚀 Run multiple AI agents securely in isolated cloud sandboxes for long tasks...

22
Experimental
67 nothingnesses/agent-images

Sandboxed OCI container images for AI coding agents, built reproducibly with Nix.

22
Experimental
68 dklymentiev/screenbox

Real virtual desktops for AI agents. MCP-native, self-hosted, fully isolated.

22
Experimental
69 madeinplutofabio/command-scope-contract

Protocol for bounded shell and CLI execution with explicit scope, policy,...

22
Experimental
70 cyruscyliu/agent-vault

Run AI coding agents in isolated Kata Container workspaces on k3s with tmux,...

22
Experimental
71 SatishoBananamoto/svx

Simulate, Verify, Execute — a safety layer for coding agents

22
Experimental
72 edlsh/pi-extension-e2b

E2B cloud sandbox integration for pi — redirects all tool execution to a...

22
Experimental
73 ClawWorksCo/lasso-sandbox

LASSO — Layered Agent Sandbox Security Orchestrator. Sandboxed execution for...

22
Experimental
74 al002/agent-fort

Security runtime for AI agents

22
Experimental
75 bird/paranoid

Isolated QEMU microVM sandboxes with WireGuard-only networking for AI agents

22
Experimental
76 Daaboulex/openviking-nix

OpenViking packaged for NixOS — agent-native context database for AI agents

22
Experimental
77 NihalKA/sandboxshift

Self-hosted AI agent sandbox with automatic local/cloud bursting

22
Experimental
78 DynamicExploit/runtm

🌐 Spin up isolated environments for coding agents to build and deploy...

22
Experimental
79 Enigma-s9v/chitin-shell

Protect AI agents by isolating LLMs from sensitive data with process...

22
Experimental
80 Rookie481/spotdb

🏖️ Create a secure, temporary data sandbox for AI workflows and exploration,...

22
Experimental
81 ian-flores/securer

Sandboxed R code execution with tool-call IPC for LLM agents

22
Experimental
82 rankgnar/agent-sandbox

Linux-native sandboxing for AI coding agents. Run Codex, Claude Code, and...

22
Experimental
83 ammmir/sandboxer

Forkable code execution server for LLMs, agents, and devs

22
Experimental
84 Arjun2729/Ithilien

Safe autonomous mode for AI coding agents. Docker sandbox + tamper-evident...

22
Experimental
85 Mykazi127/noxrunner

🔧 Interact with NoxRunner-compatible sandbox execution backends using this...

22
Experimental
86 D8k4/clampdown

Contain AI coding agents within secure container sandboxes that limit...

22
Experimental
87 us/den

Secure sandbox runtime for AI agents

21
Experimental
88 agentbox-cloud/agentbox

AgentBox SDK — Enterprise AI Sandbox Tools

21
Experimental
89 throwparty/litterbox

Review *outputs*, not *actions*: give your AI agents litter trays to poop into.

21
Experimental
90 nwcnwc/warden-proxy

A localhost proxy that gives browser-sandboxed applications safe, controlled...

20
Experimental
91 lzjever/noxrunner

Python client library and CLI for sandbox execution backends (NoxRunner...

20
Experimental
92 YujiSuzuki/ai-sandbox-dkmcp

Secure AI sandbox for Claude Code / Gemini — hide secrets, enable...

20
Experimental
93 scarab-project/scarab-runtime

Strict-confinement sandbox for autonomous AI agents. Built in Rust using...

20
Experimental
94 SudoDog-official/SudoDog

Secure sandbox for AI agents. Blocks dangerous operations, monitors...

19
Experimental
95 RutgerLubbers/cage

Put untrusted commands in a cage. Flexible file system sandboxing with...

19
Experimental
96 milyas2001/forge-agent-sandbox

FORGE - Bare-Metal Microkernel for AI Agent Sandboxing

19
Experimental
97 geraldthewes/python-executor

Currently the About section may be empty or generic. Suggested (107...

19
Experimental
98 firmo-tecnologia/devbox

Run unattended, safelly cloud code inside a container.

19
Experimental
99 brooksomics/llm-rustyolo

Secure Docker wrapper for AI coding agents with filesystem, privilege, and...

18
Experimental
100 danieljhkim/DevBox

DevBox is a minimal, language-agnostic contract that standardizes how local...

16
Experimental
101 KonghaYao/ts-sandbox-server

A secure, high-performance TypeScript/JavaScript execution sandbox server...

16
Experimental
102 RobinhoX/llm-rustyolo

🔒 Run AI agents securely with filesystem, privilege, and network isolation...

16
Experimental
103 ydevil2009/AgentFense

🔒 Enforce least-privilege access for AI agents to safely run untrusted code...

15
Experimental
104 kraaakilo/opencode-vm

Isolated Ubuntu VM setup for running OpenCode AI agents safely — Vagrant +...

15
Experimental
105 deepsarda/Nox

Nox is a secure, embeddable sandbox runtime for executing untrusted scripts...

15
Experimental
106 hanu-tayal/local-agent-sandbox

Privacy-first local AI agent runtime: sandboxed execution, sensitivity...

14
Experimental
107 aliathiullah/the-agent-sandbox-taxonomy

Provide a framework to evaluate AI agent sandboxes by scoring defense layers...

14
Experimental
108 ParthSareen/zuko

Read-only CLI sandbox for AI Agents with Touch ID for unlocking commands

14
Experimental
109 tobocop2/beebox

Secure Docker sandbox for running AI coding agents in isolated containers —...

14
Experimental
110 sourcery-zone/agent-vm

🛡️ Security by Compartmentalization for AI Coding Agents.

14
Experimental
111 iamladi/sandcaster

Run Pi agents in secure cloud sandboxes — via API, CLI, or Slack. One call....

14
Experimental
112 yevhen/klitka

Local sandbox runtime for running LLM workloads inside a microVM with...

11
Experimental
113 openagentworld/openagentworld-sandbox

A framework-agnostic sandbox for AI agent code execution — works with...

10
Experimental