Back to updates
New releaseJul 26, 2026

bromure agentic-coding-v4.5.2

Proper sandboxing for agentic coding and web browsing

Share

Bromure icon      Bromure Agentic Coding icon

Bromure

Secure, ephemeral computing in disposable Linux VMs on macOS.

→ Full details, screenshots, and downloads at bromure.io


This repo ships two sibling apps, both built on Apple's Virtualization.framework:

  • Bromure — every browser session runs in a throwaway Linux VM. Close the window, the VM is destroyed.
  • Bromure Agentic Coding — a sandboxed environment for AI coding agents (Claude Code, Codex, Grok, Kimi Code, Oh My Pi). A host-side MITM proxy swaps fake credentials for real ones on the wire so secrets never enter the VM, then adds supply-chain scanning, prompt-injection detection, PII protection, a multi-model panel, local inference, and remote access — all enforced at that one boundary.
How Bromure Agentic Coding compares

Isolation, keeping secrets out of the agent, scoping their use, scanning the supply chain, catching prompt injection: most tools pick one. Bromure does all five at a single boundary, then adds what a secret-broker never could: a model panel, local inference, and a way in from anywhere. Here is the same threat model run across the tools people reach for, and where each one stops.

A more detailed feature matrix is available at bromure.io/en/feature-matrix.

ProtectionDev Container
VS Code
nono
kernel sandbox
agent-vault
octokraft
Agent Vault
Infisical
Docker Sandboxes
microVM
Capsem
air-gapped VM
Bromure
Agentic Coding
Security
Isolation boundary
Where the blast radius stops
🟡 Same container, shared kernel🟡 Kernel allow-lists, no own kernel❌ Agent runs in place❌ Proxy only; agent unboxed✅ microVM, its own kernel✅ Hardware VM, its own kernel✅ Hardware VM, its own kernel
Keep secrets out of the agent
Can it ever read the real credential?
❌ Forwards SSH agent + git creds🟡 Blocks key files; proxies some✅ Piped in; no read path✅ Proxy attaches on the wire✅ Host proxy injects headers❌ Real API keys live in the VM✅ Stub swapped at the wire
Credential scope & approval
Per-use limits, read-only, expiry, consent
❌ No per-use scoping🟡 Approval flow + egress filter🟡 Per-secret TTL; blocks shells🟡 Egress filter per endpoint🟡 Domain allow-list; in-VM code can still use it🟡 Domain + method/path egress rules✅ Per-destination consent + TTL
Supply-chain scanning
Catching malicious / vulnerable packages
❌ No registry scanning❌ Signing only, no pkg scan❌ Out of scope❌ Out of scope❌ No package scanning❌ No package scanning✅ Age-gate, OSV, socket.dev, Depi
Prompt-injection detection
Scanning untrusted content & rules files
❌❌❌❌❌❌✅ PromptGuard + ModernBERT
PII protection
Keeping personal data from the model provider
❌❌❌❌❌❌✅ Swapped on-device, restored in replies
Audit trail
Recording what the agent did
❌ Container logs only🟡 Immutable local audit❌🟡 Request logging🟡 Request logging🟡 Full HTTP bodies in SQLite✅ Full session trace, encrypted
Supply-chain inventory (Enterprise)
A record of every package fetched
❌❌❌❌❌❌✅ Every dependency + verdict, searchable
Productivity
Agent teams
Many agents on one task, talking to each other
❌❌❌❌❌❌✅ Rooms, Switchboard, @-delegation
Token usage (Enterprise)
Which files burn the most tokens
❌❌❌❌❌❌✅ Per file, repo, and model
Multi-model fusion
A panel of models, judged & synthesized
❌❌❌❌❌❌✅ Panel + judge, on the wire
Automations
Agent runs on a schedule or on GitHub / Linear events
❌❌❌❌❌❌✅ Schedule, GitHub, Linear, chained
Local models
Any provider, or inference on your own silicon
❌❌❌❌❌❌✅ On-device MLX + any provider
Local Kubernetes
Clusters and registries next to the sandbox
🟡 DIY via Docker-in-Docker❌❌❌❌❌✅ k3s clusters + private registry
Agentic browser
A browser the agent drives to test its work
❌❌❌❌❌❌✅ Isolated Chromium, agent-driven
Reach it from anywhere
Attach to the sandbox remotely
🟡 VS Code remote❌❌❌🟡 docker exec, local❌✅ Mac, iPhone, iPad, CLI or SSH

✅ Full — built in, enforced  ·  🟡 Partial — limited or optional  ·  ❌ None — not addressed

Hiding a token isn't the same as governing its use. Docker Sandboxes keeps the raw value out of the VM — but its proxy still attaches that credential to any outbound request the sandbox makes, so a compromised package installed on the side can spend it against an allow-listed domain without ever seeing it. Only Bromure scans the package before it runs and gates each use — consent, read-only, a TTL — enforcing all five controls at one boundary the agent can't reach around. The same boundary is where Fusion, local inference, and remote access plug in.

Compiled from each project's public documentation, June 2026. Here, agent-vault refers to octokraft/agent-vault (pipe-based secret injection), distinct from Infisical's Agent Vault (HTTP credential proxy). Docker Sandboxes is an experimental preview whose brokered credentials stay usable by anything inside the VM. Bromure's fleet-wide package inventory and token-usage rollups are surfaced in Bromure Enterprise Manager. These tools move fast — see something out of date? Open an issue.

How Bromure Web compares

Every secure browser polices the web. Bromure isolates it. Talon and Island harden Chromium on your machine. Menlo isolates the web — in its cloud. Bromure runs every session in a disposable VM on your own Mac: real isolation, locally.

A more detailed feature matrix is available at bromure.io/en/feature-matrix.

Categories