
beelzebub
A secure low code deception runtime framework, leveraging AI for System Virtualization.

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

Let your AI go full send. Your home directory stays home.

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Secure code execution

Sandbox untrusted code with safe access to the host.

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Secure runtime to sandbox AI agent tasks. Run untrusted code in isolated WebAssembly environments.

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Source code of a multiple series of tutorials about the hypervisor. Available at: https://rayanfam.com/tutorials

Benchmark for evaluating AI agents on real-world tasks including vulnerability resolution, code debugging, and protein assembly in containerized…