Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
mitos — Millisecond microVM sandbox forking for AI agents on Kubernetes. Firecracker VMs that restore from memory snapshots in milliseconds, fork a running VM into N copies, and persist durable, versioned workspaces. Self-hostable, declarative CRDs. | Kitploit
Tools/GitHubGitHub/mitos-run/mitos
Container SecurityDynamic Analysis (Sandboxing)Scripting & AutomationSecurity VirtualizationCloud SecurityDevSecOpsRepository Deleted
GitHubmitos-run/mitos

mitos

Millisecond microVM sandbox forking for AI agents on Kubernetes. Firecracker VMs that restore from memory snapshots in milliseconds, fork a running VM into N copies, and persist durable, versioned workspaces. Self-hostable, declarative CRDs.

The upstream repository was not found during the latest Kitploit update check. This listing remains available for reference, but it has been removed from search results.
Website
806122 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Mitos

Mitos

Isolated, forkable computers for your AI agents.
Millisecond microVM sandbox forking on Kubernetes: fork a running VM into parallel attempts and restore from memory in tens of milliseconds.

CI Release License Go Go Report Card Docs Discord

Quickstart . Documentation . Features . Comparison . Contributing . Community

Mitos SDK: create a microVM sandbox, run code, and fork it into isolated parallel attempts


What is Mitos

Mitos gives every AI agent its own isolated computer: a hardware-isolated Firecracker microVM that runs untrusted code safely and that you can fork while it is running. A live copy-on-write fork branches one warm VM into N independent siblings in tens of milliseconds, so an agent can explore many attempts in parallel from a shared, ready state, and you pay only for the pages each sibling changes.

Run it on your own Kubernetes cluster today, where your agents' code, data, and credentials never leave your infrastructure, or on the hosted API with no nodes to manage. As far as we know, it is the only runtime that is open source, self-hostable, Kubernetes-native, and able to live-fork a running VM, all at once.

Quickstart

1. Install and authenticate

pip install mitos-run
export MITOS_API_KEY=sk-...   # a key from https://mitos.run; no Kubernetes required

The SDK defaults to the hosted endpoint. The same code runs against your own cluster or a standalone sandbox-server by setting MITOS_BASE_URL. The key is resolved from the argument or MITOS_API_KEY and is never logged.

2. Create a sandbox and run code

import mitos

sb = mitos.create("python")                  # Ready microVM sandbox (~27 ms warm-claim)
print(sb.exec("echo hello").stdout)          # hello

# Files and a stateful code interpreter hang off the same flat handle.
sb.files.write("/workspace/plan.txt", "draft")
print(sb.run_code("import math; math.sqrt(144)").text)   # 12.0

Full reference: mitos.run/docs/quickstart.

3. Fork into parallel attempts

# N-way copy-on-write fork of the live VM: each sibling lands warm and independent.
a, b = sb.fork(2)
a.exec("echo conservative > /workspace/plan.txt")
b.exec("echo aggressive  > /workspace/plan.txt")

sb.terminate()

The async client mirrors the same surface: await mitos.aio.create("python") returns an AsyncDirectSandbox with the same exec / run_code / files / create_pty / fork / terminate.

Blocking exec and run_code work on the husk default. Streaming exec (sb.exec(..., on_stdout=...)), background processes (sb.exec_background(...)), and the interactive PTY (sb.create_pty()) run on the engine path today and are being brought to the husk default; run_code returns a fail-closed KernelUnavailable until the kernel ships in the husk base image.

Run it your way

Same engine, same API, more on-ramps. Depth is one click into the docs.

Every language, two modes. Each SDK speaks the same sandbox-server REST API in direct mode (standalone or hosted), and each also has cluster mode (an AgentRun that drives the mitos.run/v1 CRDs through the Kubernetes API). Default-pool naming is byte-for-byte identical across all six.

LanguageInstallDirectClusterSDK docs
Pythonpip install mitos-runsync + asyncAgentRunsdk/python
TypeScriptnpm i @mitos/sdkyesAgentRunsdk/typescript
Gogo get github.com/mitos-run/mitos/sdk/gotyped, errors.Is-friendlyAgentRunsdk/go
Rubygem (stdlib only)yesAgentRunsdk/ruby
Rustcrate (blocking)yesAgentRunsdk/rust
JavaJDK 17 (stdlib only)yesAgentRunsdk/java

The Go SDK ships in its own nested module (github.com/mitos-run/mitos/sdk/go), so importing it never pulls the controller into your build.

Self-hosting? Same code. The Helm chart deploys the same gateway the hosted service runs, so the quickstart above works unchanged against your own cluster: point MITOS_BASE_URL at your gateway and keep everything else. Hosted and self-hosted are one experience; only the URL and who operates it differ.

Kubernetes-native control, when you want it. For platform teams that manage pools declaratively (GitOps, RBAC-scoped automation, operators), the two-tier AgentRun path skips the gateway and drives the mitos.run/v1 CRDs through the Kubernetes API directly:

from mitos import AgentRun

c = AgentRun()                                   # kubeconfig or in-cluster; autodetected
sb = c.sandbox("python", ready=True)             # claims a warm sandbox, waits Ready
print(sb.exec("python -c 'print(40 + 2)'").stdout)   # 42

fork_a, fork_b = sb.fork(2)                       # fork against shared warmed state
sb.terminate()

c.sandbox("python") lazily creates a default pool if you have none; pass pool="my-pool" to use an existing one. Errors raise AgentRunError(code, cause, remediation). AsyncAgentRun mirrors the hot paths and adds create_pty() over WebSocket.

CLI and MCP.

The mitos CLI works against the hosted gateway (no cluster needed) or your own Kubernetes cluster:

go install mitos.run/mitos/cmd/mitos@latest      # requires a Go toolchain