Agent Code Sandboxing AI Agents

Tools and platforms for isolating, containerizing, and safely executing untrusted code from AI agents using Docker, VMs, WebSockets, or namespace-based sandboxes. Does NOT include general container orchestration, deployment platforms, or security monitoring without execution isolation capabilities.

There are 113 agent code sandboxing agents tracked. 3 score above 70 (verified tier). The highest-rated is e2b-dev/E2B at 79/100 with 11,263 stars. 9 of the top 10 are actively maintained.

Get all 113 projects as JSON

curl "https://pt-edge.onrender.com/api/v1/datasets/quality?domain=agents&subcategory=agent-code-sandboxing&limit=20"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.

# Agent Score Tier
1 e2b-dev/E2B

Open-source, secure environment with real-world tools for enterprise-grade agents.

79
Verified
2 alibaba/OpenSandbox

OpenSandbox is a general-purpose sandbox platform for AI applications,...

74
Verified
3 e2b-dev/infra

Infrastructure that's powering E2B Cloud.

73
Verified
4 always-further/nono

Secure, kernel-enforced sandbox CLI and SDKs for AI agents. Capability-based...

60
Established
5 boxlite-ai/boxlite

Sandboxes for every agent. Embeddable, stateful, snapshots, and hardware isolation.

59
Established
6 zerobootdev/zeroboot

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

57
Established
7 eugene1g/agent-safehouse

Sandbox your local AI agents so they can read/write only what they need

56
Established
8 agbcloud/agbcloud-sdk

AI-native cross-platform sandboxes for developers, featuring multimodal...

54
Established
9 adammiribyan/zeroboot

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

54
Established
10 multikernel/sandlock

Lightweight process-based sandbox for Linux, no container, no VM, no root.

52
Established
11 rivet-dev/secure-exec

Secure Node.js Execution Without a Sandbox A lightweight library for secure...

50
Established
12 HACKE-RC/Bandsox

Sanboxes for AI agents and humans

49
Emerging
13 dtormoen/tsk-tsk

Keeping your agents out of trouble with sandboxed coding agent automation

48
Emerging
14 tomascupr/sandstorm

Run Claude agents in secure cloud sandboxes — via API, CLI, or Slack. One...

47
Emerging
15 adarsh9780/safe-py-runner

A lightweight, secure-by-default Python code runner designed for LLM agents.

45
Emerging
16 angelorc/vmsan

Firecracker made simple. Spin up secure microVMs in milliseconds, from...

44
Emerging
17 onyx-dot-app/python-sandbox

Secure and lightweight Python code execution environment for LLMs

44
Emerging
18 mavdol/capsule

A secure, durable runtime to sandbox AI agent tasks. Run untrusted code in...

44
Emerging
19 Th0rgal/sandboxed.sh

Self-hosted orchestrator for AI autonomous agents. Run Claude Code & Open...

42
Emerging
20 Parassharmaa/agent-sandbox

A sandboxed execution environment for AI agents via WASM

41
Emerging
21 rpfilomeno/opencode-docker

Stop prompt injection catastrophe! Run your AI Agents in secure isolated...

41
Emerging
22 railroad-dev/railroad

Run Claude Code at full speed, safely. OS-level command blocking with no...

40
Emerging
23 runtm-ai/runtm

Open-source sandboxes where coding agents build and deploy. Spin up isolated...

39
Emerging
24 projecteru2/cocoon

Lightweight MicroVM VMM built on Cloud Hypervisor for AI

39
Emerging
25 jamesmurdza/upstream-agents

Run AI coding agents in isolated sandboxes connected to your GitHub repositories

39
Emerging
26 branchbox/branchbox

Parallel, isolated dev environments for humans and AI coding agents. Real...

39
Emerging
27 stacklok/brood-box

CLI tool for running coding agents inside hardware-isolated microVMs

38
Emerging
28 EXboys/skilllite

A lightweight secure Self-evolution engine built in Rust, featuring a...

38
Emerging
29 akshayaggarwal99/boxed

The Sovereign Code Execution Engine for AI Agents. Run untrusted code safely...

37
Emerging
30 gizmax/Sandcastle

Production-ready AI agent workflow orchestrator. 63 integrations, EU AI Act...

37
Emerging
31 getlark/runtimeuse

Run AI agents inside sandboxes over WebSockets

36
Emerging
32 legionus/devkit

The project allows you to manage isolated containers with AI agents

36
Emerging
33 Raynan00/sandpy

Browser-native Python sandbox for AI agents

35
Emerging
34 HappyHackingSpace/sindoq

AI Sandbox

35
Emerging
35 ixchio/agent-sandbox-runtime

A secure runtime for self-correcting AI agents with Docker sandboxing.

35
Emerging
36 STONE-CELL-SPF-JOSEPH-STONE/SPFsmartGATE

AI Security Gateway — Compiled Rust enforcement between AI agents and your...

34
Emerging
37 89luca89/clampdown

Run AI coding agents in hardened container sandboxes.

34
Emerging
38 reoring/botbox

Kubernetes sidecar that sandboxes container egress. Deny-by-default...

32
Emerging
39 deevus/pixels

Disposable Linux containers for AI coding agents, with extensible backends

32
Emerging
40 joshualamerton/agentic-sandbox

Simulation environment for testing and validating autonomous agents

32
Emerging
41 the-void-ia/void-box

Composable agent runtime with enforced isolation boundaries

32
Emerging
42 foundry-works/foundry-sandbox

Ephemeral, batteries-included Docker workspaces that isolate AI coding...

32
Emerging
43 haasonsaas/capsule-run

Lightweight, secure sandboxed command execution for AI agents

31
Emerging
44 sauravbhattacharya001/ai

Contract-enforced sandbox for studying AI agent self-replication safety

30
Emerging
45 ammmir/sandboxer

Forkable code execution server for LLMs, agents, and devs

29
Experimental
46 Orellius/Laminae

AI personality, safety, red-teaming, and sandboxing in Rust SDK.

29
Experimental
47 sevorix/sevorix-lite

Sevorix Lite is a Rust-native, open-source runtime containment engine for...

29
Experimental
48 Parassharmaa/agent-fetch

Sandboxed HTTP client with SSRF protection for AI agents. Prevents DNS...

28
Experimental
49 arcboxlabs/arcbox

Run AI agents on real and isolated machines — own kernel, filesystem, and...

28
Experimental
50 seznam/jailoc

🔒 Jail your AI agents — sandboxed Docker environments with network isolation...

27
Experimental
51 agentbox-cloud/agentbox

AgentBox SDK — Enterprise AI Sandbox Tools

27
Experimental
52 hyperterse/sandboxer

Single, consistent interface to run code, manage files, and control isolated...

26
Experimental
53 DavidKim0326/DUDA

Isolation Guardian for Claude Code — Prevent AI agents from breaking...

26
Experimental
54 kajogo777/the-agent-sandbox-taxonomy

An open taxonomy and scoring framework for evaluating AI agent sandboxes: 7...

26
Experimental
55 opencapsule/opencapsule

Secure Code Execution Runtime for AI Agents

26
Experimental
56 AxeForging/aigate

OS-level sandbox for AI coding agents - kernel-enforced file, command, and...

26
Experimental
57 nhevers/agent-sandbox

Sandboxed code execution for AI agents

25
Experimental
58 numcys/sudomode

The Missing sudo Command for AI Agents.

25
Experimental
59 danievanzyl/pyro

Open-source Firecracker microVM sandbox platform for AI agents

25
Experimental
60 c4rb0nx1/tuprwre

That install command your AI agent just ran? Never touched your host....

25
Experimental
61 lzjever/noxrunner

Python client library and CLI for sandbox execution backends (NoxRunner...

24
Experimental
62 dredozubov/hazmat

macOS containment for AI agents — user isolation, kernel sandbox, pf...

24
Experimental
63 Mickdownunder/atlas-validation-layer

Bounded validation and sandbox layer for the Operator research control plane

23
Experimental
64 Embedded-Focus/agent-circus

Run AI coding agents in sandboxed containers communicate via ACP

23
Experimental
65 KometzRobot/capsule-spec

Open tools for AI identity persistence — Capsule Spec, Loop Harness, Cinder Enhanced

23
Experimental
66 throwparty/litterbox

Review *outputs*, not *actions*: give your AI agents litter trays to poop into.

23
Experimental
67 qhkm/zeptocapsule

Isolation sandbox for AI agents — process, namespace, and Firecracker capsules

23
Experimental
68 us/den

Secure sandbox runtime for AI agents

23
Experimental
69 liut/strata

Lightweight Session Sandbox Service — Isolated Shell Environments via...

23
Experimental
70 Mykazi127/noxrunner

🔧 Interact with NoxRunner-compatible sandbox execution backends using this...

22
Experimental
71 D8k4/clampdown

Contain AI coding agents within secure container sandboxes that limit...

22
Experimental
72 bird/paranoid

Isolated QEMU microVM sandboxes with WireGuard-only networking for AI agents

22
Experimental
73 Daaboulex/openviking-nix

OpenViking packaged for NixOS — agent-native context database for AI agents

22
Experimental
74 YujiSuzuki/ai-sandbox-dkmcp

Secure AI sandbox for Claude Code / Gemini — hide secrets, enable...

22
Experimental
75 ydevil2009/AgentFense

🔒 Enforce least-privilege access for AI agents to safely run untrusted code...

22
Experimental
76 nwcnwc/warden-proxy

A localhost proxy that gives browser-sandboxed applications safe, controlled...

22
Experimental
77 heromen22/sandstorm

🚀 Run multiple AI agents securely in isolated cloud sandboxes for long tasks...

22
Experimental
78 nothingnesses/agent-images

Sandboxed OCI container images for AI coding agents, built reproducibly with Nix.

22
Experimental
79 dklymentiev/screenbox

Real virtual desktops for AI agents. MCP-native, self-hosted, fully isolated.

22
Experimental
80 madeinplutofabio/command-scope-contract

Protocol for bounded shell and CLI execution with explicit scope, policy,...

22
Experimental
81 cyruscyliu/agent-vault

Run AI coding agents in isolated Kata Container workspaces on k3s with tmux,...

22
Experimental
82 SatishoBananamoto/svx

Simulate, Verify, Execute — a safety layer for coding agents

22
Experimental
83 edlsh/pi-extension-e2b

E2B cloud sandbox integration for pi — redirects all tool execution to a...

22
Experimental
84 ClawWorksCo/lasso-sandbox

LASSO — Layered Agent Sandbox Security Orchestrator. Sandboxed execution for...

22
Experimental
85 al002/agent-fort

Security runtime for AI agents

22
Experimental
86 0rzech/vibe-containers

Simple sandbox Podman containers for Mistral Vibe

22
Experimental
87 geraldthewes/python-executor

Currently the About section may be empty or generic. Suggested (107...

21
Experimental
88 rankgnar/agent-sandbox

Linux-native sandboxing for AI coding agents. Run Codex, Claude Code, and...

21
Experimental
89 ian-flores/securer

Sandboxed R code execution with tool-call IPC for LLM agents

21
Experimental
90 firmo-tecnologia/devbox

Run unattended, safelly cloud code inside a container.

21
Experimental
91 SudoDog-official/SudoDog

Secure sandbox for AI agents. Blocks dangerous operations, monitors...

21
Experimental
92 Enigma-s9v/chitin-shell

Protect AI agents by isolating LLMs from sensitive data with process...

21
Experimental
93 Rookie481/spotdb

🏖️ Create a secure, temporary data sandbox for AI workflows and exploration,...

21
Experimental
94 Arjun2729/Ithilien

Safe autonomous mode for AI coding agents. Docker sandbox + tamper-evident...

21
Experimental
95 milyas2001/forge-agent-sandbox

FORGE - Bare-Metal Microkernel for AI Agent Sandboxing

21
Experimental
96 DynamicExploit/runtm

🌐 Spin up isolated environments for coding agents to build and deploy...

21
Experimental
97 NihalKA/sandboxshift

Self-hosted AI agent sandbox with automatic local/cloud bursting

21
Experimental
98 scarab-project/scarab-runtime

Strict-confinement sandbox for autonomous AI agents. Built in Rust using...

20
Experimental
99 sourcery-zone/agent-vm

🛡️ Security by Compartmentalization for AI Coding Agents.

20
Experimental
100 KonghaYao/ts-sandbox-server

A secure, high-performance TypeScript/JavaScript execution sandbox server...

20
Experimental
101 brooksomics/llm-rustyolo

Secure Docker wrapper for AI coding agents with filesystem, privilege, and...

19
Experimental
102 kraaakilo/opencode-vm

Isolated Ubuntu VM setup for running OpenCode AI agents safely — Vagrant +...

17
Experimental
103 RutgerLubbers/cage

Put untrusted commands in a cage. Flexible file system sandboxing with...

17
Experimental
104 tobocop2/beebox

Secure Docker sandbox for running AI coding agents in isolated containers —...

16
Experimental
105 danieljhkim/DevBox

DevBox is a minimal, language-agnostic contract that standardizes how local...

16
Experimental
106 deepsarda/Nox

Nox is a secure, embeddable sandbox runtime for executing untrusted scripts...

15
Experimental
107 RobinhoX/llm-rustyolo

🔒 Run AI agents securely with filesystem, privilege, and network isolation...

15
Experimental
108 hanu-tayal/local-agent-sandbox

Privacy-first local AI agent runtime: sandboxed execution, sensitivity...

14
Experimental
109 aliathiullah/the-agent-sandbox-taxonomy

Provide a framework to evaluate AI agent sandboxes by scoring defense layers...

14
Experimental
110 ParthSareen/zuko

Read-only CLI sandbox for AI Agents with Touch ID for unlocking commands

14
Experimental
111 iamladi/sandcaster

Run Pi agents in secure cloud sandboxes — via API, CLI, or Slack. One call....

13
Experimental
112 yevhen/klitka

Local sandbox runtime for running LLM workloads inside a microVM with...

13
Experimental
113 openagentworld/openagentworld-sandbox

A framework-agnostic sandbox for AI agent code execution — works with...

10
Experimental