
sandbox-runtime
A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

VirusTotal Wanna Be - Now with 100% more Hipster

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Lightweight, container-free sandbox for running commands with network and filesystem restrictions

A local sandbox for your AI agents

Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

A Linux Host-based Intrusion Detection System based on eBPF.

Secure runtime to sandbox AI agent tasks. Run untrusted code in isolated WebAssembly environments.

Proper sandboxing for agentic coding and web browsing

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

Run untrusted AI code safely, fast

Ultrafast CLI on Apple Silicon macOS for fast, sandboxed development and LLM agents.


eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.
