
zeroboot
Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

Proof-of-concept exploit for CVE-2018-1002105, a Kubernetes privilege escalation vulnerability allowing unauthorized command execution in pods via…

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

Millisecond microVM sandbox forking for AI agents on Kubernetes. Firecracker VMs that restore from memory snapshots in milliseconds, fork a running…

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.

Give coding agents a disposable Linux VM, not your laptop

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…