box
Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support pla
- agentic-ai
- agents
- ai
- ai-agents
- ai-safety
- containment
- egress
- harness
- linux
- llm
- macos
- mcp
- policy
- rust
- sandbox
- Stars
- 76
- Forks
- 3
- + today
- +2
- Created
- 5d
Ranking data as of October 7, 2026 (UTC).
Star History
Today, hour by hour
Overview
Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support pla It ranks #886 on GitTiger, gaining +2 stars on October 7, 2026 (UTC).
The project is written in Rust and has 3 forks. It was created 5d ago.
git clone https://github.com/strands-agents/box.git
cd box
# see README for setup