
bromure agentic-coding-v4.5.4
Proper sandboxing for agentic coding and web browsing
Bromure
Secure, ephemeral computing in disposable Linux VMs on macOS.
→ Full details, screenshots, and downloads at bromure.io
This repo ships two sibling apps, both built on Apple's Virtualization.framework:
- Bromure — every browser session runs in a throwaway Linux VM. Close the window, the VM is destroyed.
- Bromure Agentic Coding — a sandboxed environment for AI coding agents (Claude Code, Codex, Grok, Kimi Code, Oh My Pi). A host-side MITM proxy swaps fake credentials for real ones on the wire so secrets never enter the VM, then adds supply-chain scanning, prompt-injection detection, PII protection, a multi-model panel, local inference, and remote access — all enforced at that one boundary.
How Bromure Agentic Coding compares
Isolation, keeping secrets out of the agent, scoping their use, scanning the supply chain, catching prompt injection: most tools pick one. Bromure does all five at a single boundary, then adds what a secret-broker never could: a model panel, local inference, and a way in from anywhere. Here is the same threat model run across the tools people reach for, and where each one stops.
A more detailed feature matrix is available at bromure.io/en/feature-matrix.
| Protection | Dev Container VS Code | nono kernel sandbox | agent-vault octokraft | Agent Vault Infisical | Docker Sandboxes microVM | Capsem air-gapped VM | Bromure Agentic Coding |
|---|---|---|---|---|---|---|---|
| Security | |||||||
| Isolation boundary Where the blast radius stops | 🟡 Same container, shared kernel | 🟡 Kernel allow-lists, no own kernel | ❌ Agent runs in place | ❌ Proxy only; agent unboxed | ✅ microVM, its own kernel | ✅ Hardware VM, its own kernel | ✅ Hardware VM, its own kernel |
| Keep secrets out of the agent Can it ever read the real credential? | ❌ Forwards SSH agent + git creds | 🟡 Blocks key files; proxies some | ✅ Piped in; no read path | ✅ Proxy attaches on the wire | ✅ Host proxy injects headers | ❌ Real API keys live in the VM | ✅ Stub swapped at the wire |
| Credential scope & approval Per-use limits, read-only, expiry, consent | ❌ No per-use scoping | 🟡 Approval flow + egress filter | 🟡 Per-secret TTL; blocks shells | 🟡 Egress filter per endpoint | 🟡 Domain allow-list; in-VM code can still use it | 🟡 Domain + method/path egress rules | ✅ Per-destination consent + TTL |
| Supply-chain scanning Catching malicious / vulnerable packages | ❌ No registry scanning | ❌ Signing only, no pkg scan | ❌ Out of scope | ❌ Out of scope | ❌ No package scanning | ❌ No package scanning | ✅ Age-gate, OSV, socket.dev, Depi |
| Prompt-injection detection Scanning untrusted content & rules files | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ PromptGuard + ModernBERT |
| PII protection Keeping personal data from the model provider | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ Swapped on-device, restored in replies |
| Audit trail Recording what the agent did | ❌ Container logs only | 🟡 Immutable local audit | ❌ | 🟡 Request logging | 🟡 Request logging | 🟡 Full HTTP bodies in SQLite | ✅ Full session trace, encrypted |
| Supply-chain inventory (Enterprise) A record of every package fetched | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ Every dependency + verdict, searchable |
| Productivity | |||||||
| Agent teams Many agents on one task, talking to each other | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ Rooms, Switchboard, @-delegation |
| Token usage (Enterprise) Which files burn the most tokens | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ Per file, repo, and model |
| Multi-model fusion A panel of models, judged & synthesized | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ Panel + judge, on the wire |
| Automations Agent runs on a schedule or on GitHub / Linear events | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ Schedule, GitHub, Linear, chained |
| Local models Any provider, or inference on your own silicon | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ On-device MLX + any provider |
| Local Kubernetes Clusters and registries next to the sandbox | 🟡 DIY via Docker-in-Docker | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ k3s clusters + private registry |
| Agentic browser A browser the agent drives to test its work | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ Isolated Chromium, agent-driven |
| Reach it from anywhere Attach to the sandbox remotely | 🟡 VS Code remote | ❌ | ❌ | ❌ | 🟡 docker exec, local | ❌ | ✅ Mac, iPhone, iPad, CLI or SSH |
✅ Full — built in, enforced · 🟡 Partial — limited or optional · ❌ None — not addressed
Hiding a token isn't the same as governing its use. Docker Sandboxes keeps the raw value out of the VM — but its proxy still attaches that credential to any outbound request the sandbox makes, so a compromised package installed on the side can spend it against an allow-listed domain without ever seeing it. Only Bromure scans the package before it runs and gates each use — consent, read-only, a TTL — enforcing all five controls at one boundary the agent can't reach around. The same boundary is where Fusion, local inference, and remote access plug in.
Compiled from each project's public documentation, June 2026. Here, agent-vault refers to octokraft/agent-vault (pipe-based secret injection), distinct from Infisical's Agent Vault (HTTP credential proxy). Docker Sandboxes is an experimental preview whose brokered credentials stay usable by anything inside the VM. Bromure's fleet-wide package inventory and token-usage rollups are surfaced in Bromure Enterprise Manager. These tools move fast — see something out of date? Open an issue.
How Bromure Web compares
Every secure browser polices the web. Bromure isolates it. Talon and Island harden Chromium on your machine. Menlo isolates the web — in its cloud. Bromure runs every session in a disposable VM on your own Mac: real isolation, locally.
A more detailed feature matrix is available at bromure.io/en/feature-matrix.