Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
agentbox — Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253. | Kitploit
Tools/GitHubGitHub/siyad01/agentbox
Cloud Infrastructure SecurityContainer SecurityEncryption/Decryption ToolsSecurity VirtualizationDevSecOpsIdentity & Access Management (IAM)
GitHubsiyad01/agentbox

agentbox

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

View Repository
1244 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ AgentBox

The open-source sandboxed runtime for AI agents

Run AI agents with confidence. Every agent gets its own permission scope, credential vault, audit trail, and kill switch.

Build License: Apache 2.0 Go Version Tests Platform


Why AgentBox exists

On January 27, 2026, CVE-2026-25253 became the first CVE ever assigned to an agentic AI system. A critical WebSocket hijacking vulnerability in OpenClaw enabled one-click remote code execution against any exposed instance — including those bound only to localhost.

That same week, the ClawHavoc campaign infiltrated 341+ malicious skills into OpenClaw's marketplace. Every skill installed from ClawHub ran with the same permissions as OpenClaw itself — full disk access, OAuth tokens, API keys. No sandbox. No audit trail. No kill switch.

"Installing a skill from ClawHub grants it access to the same resources as OpenClaw itself. There is no sandbox isolation between skills by default." — DEV Community security analysis, April 2026

The numbers:

  • 138+ CVEs in OpenClaw in 2026 alone
  • 135,000+ exposed instances across 82 countries
  • 341 confirmed malicious skills (12% of the entire registry)
  • 1.5 million agent API tokens exposed in plaintext
  • Microsoft: "It is not appropriate to run it on a standard personal or corporate machine."

AgentBox is the structural fix. Not a patch — a runtime.


What AgentBox does

Every agent you run gets:

ProtectionHow
Zero-trust permissionsAgents declare exactly what they need. Nothing else is accessible.
Kernel-level isolationgVisor intercepts every syscall. Prompt injection cannot cross this boundary.
Credential vaultAES-256-GCM encryption. Agents never see raw secrets — only scoped tokens.
Immutable audit logSHA-256 hash chain. Every action logged. Tamper-evident.
Kill switchTerminate any agent in under 100ms. Auto-kill on limit breach.
Resource limitsTime, memory, request count — enforced at runtime, not at config.
Before AgentBox                    After AgentBox
─────────────────                  ──────────────
Agent → full disk ❌               Agent → allowed paths only ✅
Agent → all network ❌             Agent → allowed hosts only ✅
Agent → raw secrets ❌             Agent → scoped tokens ✅
No audit trail ❌                  Every action logged ✅
No kill switch ❌                  Kill in <100ms ✅
Skills run as root ❌              Kernel-isolated sandbox ✅

Quick start

# Install
go install github.com/siyad01/agentbox/cmd/agentbox@latest

# Validate a manifest before running
agentbox validate manifests/email-sorter.yaml

# Run an agent in a sandbox
agentbox run --manifest manifests/email-sorter.yaml python agent.py

# View what the agent did
agentbox audit --log logs/email-sorter-audit.log

# Verify the log hasn't been tampered with
agentbox verify logs/email-sorter-audit.log

# Manage secrets
agentbox vault add ANTHROPIC_API_KEY
agentbox vault list

The manifest

Every agent declares exactly what it needs. Nothing not listed is accessible.

name: "email-sorter"
version: "1.0.0"
description: "Reads inbox, categorizes emails, writes to sorted folder"
runtime: docker        # or: gvisor (kernel-level), firecracker (MicroVM)

permissions:
  filesystem:
    read:
      - "~/Documents/inbox"
    write:
      - "~/Documents/sorted"
    deny:                      # ALWAYS blocked — even if in read list
      - "~/.ssh"
      - "~/.aws"
      - "~/.config"
      - "/etc"

  network:
    allow:
      - "api.anthropic.com"
      - "gmail.googleapis.com"
    deny:
      - "*"                    # block everything else

  tools:
    allow:
      - "read_file"
      - "write_file"
      - "list_*"
    deny:
      - "execute_shell"        # no shell access, ever
      - "*_delete"             # no deletion tools

  credentials:
    - ANTHROPIC_API_KEY        # injected from vault at runtime
    - GMAIL_TOKEN              # agent never sees the raw value

limits:
  max_tokens:    50000         # LLM token budget
  max_duration:  "30m"         # killed after 30 minutes
  max_memory_mb: 256           # RAM ceiling
  max_requests:  500           # max tool invocations

audit:
  log_level: full
  alert_on:
    - filesystem_deny
    - network_deny
    - token_budget_80pct
  log_path: "logs/email-sorter-audit.log"

How it works

agentbox run --manifest agent.yaml python agent.py
         │
         ▼
┌─────────────────────────────────────────────────────┐
│                 Policy Engine                        │
│  Parses manifest → builds allow/deny lists          │
│  Validates signatures → rejects unsigned skills     │
│  Injects credentials from vault                     │
└──────────────────────┬──────────────────────────────┘
                       │
                       ▼
┌─────────────────────────────────────────────────────┐
│              Isolation Layer                         │
│                                                     │
│  Docker  → container + seccomp + cap-drop           │
│  gVisor  → user-space kernel, syscall interception  │
│  Firecracker → dedicated MicroVM kernel per agent   │
│                                                     │
│  Filesystem: only declared paths mounted            │
│  Network:    only declared hosts reachable          │
│  Capabilities: ALL dropped, none added back         │
└──────────────────────┬──────────────────────────────┘
                       │
          ┌────────────┼────────────┐
          ▼            ▼            ▼
   Audit Logger   Credential    Resource
   (hash-chain)     Vault       Monitor
   every action   AES-256-GCM  auto-kill
   logged         scoped tokens on limit

Why gVisor stops prompt injection

Every other sandbox stops at the container boundary. An agent exploiting a kernel vulnerability can escape.

gVisor intercepts every syscall before it reaches the host kernel:

Agent tries: write("/home/user/.ssh/id_rsa")
                    │
                    ▼
         gVisor user-space kernel
                    │
         Path in deny list? → YES
                    │
                    ▼
         EPERM returned immediately
         Host kernel never sees this syscall
         Prompt injection cannot cross this layer

CLI reference

agentbox <command> [options]

Commands:
  run       Run an agent in a sandbox
  validate  Validate a manifest file
  kill      Terminate a running agent
  audit     View agent audit logs
  verify    Verify audit log integrity
  vault     Manage encrypted credentials
  serve     Start the REST API server
  version   Show version

Examples:
  agentbox validate manifests/email-sorter.yaml
  agentbox run --manifest manifests/email-sorter.yaml python agent.py
  agentbox kill agent-abc123
  agentbox audit --log logs/email-sorter.log --deny
  agentbox audit --log logs/email-sorter.log --last 1h
  agentbox verify logs/email-sorter.log
  agentbox vault add ANTHROPIC_API_KEY
  agentbox vault list
  agentbox vault delete OLD_KEY
  agentbox serve :8081

REST API

Start with agentbox serve (default: :8081).

Download Tool