
agentbox
Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

Detection and analysis toolkit for CVE-2026-31431 Linux LPE, providing Python and PowerShell scanners, YARA rules, and forensic analysis for active…

Scans Infrastructure as Code files for security misconfigurations and vulnerabilities using KICS, with Bitbucket Code Insights reporting.

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

eBPF-based runtime detector for container breakout vulnerabilities in runc and Docker, monitoring syscalls and Docker daemon calls to detect…

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

A service that analyzes docker images and scans for vulnerabilities

Linux application sandboxing and distribution framework

Protect against malicious open source packages 🤖

Real-time, container-based file scanning at enterprise scale

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Secure runtime to sandbox AI agent tasks. Run untrusted code in isolated WebAssembly environments.

Your agent is a security risk, so treat it like one. yoloAI does AI agent sandboxing right.

Open-source secret scanner in Rust

ArmourBird CSF - Container Security Framework

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…