
Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.
The open-source sandboxed runtime for AI agents
Run AI agents with confidence. Every agent gets its own permission scope, credential vault, audit trail, and kill switch.
On January 27, 2026, CVE-2026-25253 became the first CVE ever assigned to an agentic AI system. A critical WebSocket hijacking vulnerability in OpenClaw enabled one-click remote code execution against any exposed instance — including those bound only to localhost.
That same week, the ClawHavoc campaign infiltrated 341+ malicious skills into OpenClaw's marketplace. Every skill installed from ClawHub ran with the same permissions as OpenClaw itself — full disk access, OAuth tokens, API keys. No sandbox. No audit trail. No kill switch.
"Installing a skill from ClawHub grants it access to the same resources as OpenClaw itself. There is no sandbox isolation between skills by default." — DEV Community security analysis, April 2026
The numbers:
AgentBox is the structural fix. Not a patch — a runtime.
Every agent you run gets:
| Protection | How |
|---|---|
| Zero-trust permissions | Agents declare exactly what they need. Nothing else is accessible. |
| Kernel-level isolation | gVisor intercepts every syscall. Prompt injection cannot cross this boundary. |
| Credential vault | AES-256-GCM encryption. Agents never see raw secrets — only scoped tokens. |
| Immutable audit log | SHA-256 hash chain. Every action logged. Tamper-evident. |
| Kill switch | Terminate any agent in under 100ms. Auto-kill on limit breach. |
| Resource limits | Time, memory, request count — enforced at runtime, not at config. |
Before AgentBox After AgentBox
───────────────── ──────────────
Agent → full disk ❌ Agent → allowed paths only ✅
Agent → all network ❌ Agent → allowed hosts only ✅
Agent → raw secrets ❌ Agent → scoped tokens ✅
No audit trail ❌ Every action logged ✅
No kill switch ❌ Kill in <100ms ✅
Skills run as root ❌ Kernel-isolated sandbox ✅
# Install
go install github.com/siyad01/agentbox/cmd/agentbox@latest
# Validate a manifest before running
agentbox validate manifests/email-sorter.yaml
# Run an agent in a sandbox
agentbox run --manifest manifests/email-sorter.yaml python agent.py
# View what the agent did
agentbox audit --log logs/email-sorter-audit.log
# Verify the log hasn't been tampered with
agentbox verify logs/email-sorter-audit.log
# Manage secrets
agentbox vault add ANTHROPIC_API_KEY
agentbox vault list
Every agent declares exactly what it needs. Nothing not listed is accessible.
name: "email-sorter"
version: "1.0.0"
description: "Reads inbox, categorizes emails, writes to sorted folder"
runtime: docker # or: gvisor (kernel-level), firecracker (MicroVM)
permissions:
filesystem:
read:
- "~/Documents/inbox"
write:
- "~/Documents/sorted"
deny: # ALWAYS blocked — even if in read list
- "~/.ssh"
- "~/.aws"
- "~/.config"
- "/etc"
network:
allow:
- "api.anthropic.com"
- "gmail.googleapis.com"
deny:
- "*" # block everything else
tools:
allow:
- "read_file"
- "write_file"
- "list_*"
deny:
- "execute_shell" # no shell access, ever
- "*_delete" # no deletion tools
credentials:
- ANTHROPIC_API_KEY # injected from vault at runtime
- GMAIL_TOKEN # agent never sees the raw value
limits:
max_tokens: 50000 # LLM token budget
max_duration: "30m" # killed after 30 minutes
max_memory_mb: 256 # RAM ceiling
max_requests: 500 # max tool invocations
audit:
log_level: full
alert_on:
- filesystem_deny
- network_deny
- token_budget_80pct
log_path: "logs/email-sorter-audit.log"
agentbox run --manifest agent.yaml python agent.py
│
▼
┌─────────────────────────────────────────────────────┐
│ Policy Engine │
│ Parses manifest → builds allow/deny lists │
│ Validates signatures → rejects unsigned skills │
│ Injects credentials from vault │
└──────────────────────┬──────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────┐
│ Isolation Layer │
│ │
│ Docker → container + seccomp + cap-drop │
│ gVisor → user-space kernel, syscall interception │
│ Firecracker → dedicated MicroVM kernel per agent │
│ │
│ Filesystem: only declared paths mounted │
│ Network: only declared hosts reachable │
│ Capabilities: ALL dropped, none added back │
└──────────────────────┬──────────────────────────────┘
│
┌────────────┼────────────┐
▼ ▼ ▼
Audit Logger Credential Resource
(hash-chain) Vault Monitor
every action AES-256-GCM auto-kill
logged scoped tokens on limit
Every other sandbox stops at the container boundary. An agent exploiting a kernel vulnerability can escape.
gVisor intercepts every syscall before it reaches the host kernel:
Agent tries: write("/home/user/.ssh/id_rsa")
│
▼
gVisor user-space kernel
│
Path in deny list? → YES
│
▼
EPERM returned immediately
Host kernel never sees this syscall
Prompt injection cannot cross this layer
agentbox <command> [options]
Commands:
run Run an agent in a sandbox
validate Validate a manifest file
kill Terminate a running agent
audit View agent audit logs
verify Verify audit log integrity
vault Manage encrypted credentials
serve Start the REST API server
version Show version
Examples:
agentbox validate manifests/email-sorter.yaml
agentbox run --manifest manifests/email-sorter.yaml python agent.py
agentbox kill agent-abc123
agentbox audit --log logs/email-sorter.log --deny
agentbox audit --log logs/email-sorter.log --last 1h
agentbox verify logs/email-sorter.log
agentbox vault add ANTHROPIC_API_KEY
agentbox vault list
agentbox vault delete OLD_KEY
agentbox serve :8081
Start with agentbox serve (default: :8081).