Code GenerationOpen_source
Sandbox Runtime logo

Sandbox Runtime

Container-free OS-level sandboxing for AI agents and processes

Overview

About Sandbox Runtime

Sandbox Runtime is a lightweight tool from Anthropic for restricting what a process can read, write and reach on the network, enforced at the operating system level and without requiring a container. It was built for Claude Code and released open source as a research preview, on the argument that safer agents are a problem the whole ecosystem needs solved rather than a competitive advantage worth hoarding.

The technical choice that makes it interesting is the absence of a container. It uses what the operating system already provides, sandbox-exec on macOS and bubblewrap on Linux, combined with a filtering proxy for network access. That keeps startup cheap and the footprint small, which matters because the alternative, wrapping every agent invocation in Docker, is heavy enough that people skip it and then run agents unrestricted instead. The things it can constrain are exactly the things worth worrying about right now: agents, local MCP servers, and arbitrary bash commands an agent decides to run. Two caveats deserve stating plainly. It is a research preview under an experimental organisation, so interfaces can move. And OS-level sandboxing is a meaningful boundary but not the same guarantee as a virtual machine, so match it to your actual threat model rather than assuming it is equivalent to full isolation.

Pricing

From $0/mo

Free tier

Free and open source under Apache-2.0. Released as a research preview, so treat it as evolving rather than settled.

Checked 2026-09-07

Details

GitHub Stars 5,049
Forks 413
Data from: GitHub • Website•Updated: Aug 24, 2026
devopsinfrastructuresecurityopen-source