
kern
Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

Secure and fast microVMs for serverless computing.

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Domain-specific language for writing fast functional device models for virtual platforms. Compiles DML to C with API calls tailored for the Intel…

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Sandbox untrusted code with safe access to the host.

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Easily create full virtual machines that are sandboxed for development or computer use models.

A fuzzer for full VM kernel/driver targets

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Ultrafast CLI on Apple Silicon macOS for fast, sandboxed development and LLM agents.

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

Run untrusted AI code safely, fast

Script to install prerequisites for deploying GOAD on Ubuntu Linux 22.04

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…