
minicps
Real-time simulation framework for cyber-physical systems with physical process/control device models and Mininet-based network emulation, built for…

Real-time simulation framework for cyber-physical systems with physical process/control device models and Mininet-based network emulation, built for…

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

Provides supplemental files and Debian package sources for a specialized Linux distro focused on malware analysis, reverse engineering, and digital…

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

Docker-based sandbox for coding agents with isolated environments, preinstalled agent tooling, service control, and workspace bootstrap for secure…

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Ultrafast CLI on Apple Silicon macOS for fast, sandboxed development and LLM agents.

Millisecond microVM sandbox forking for AI agents on Kubernetes. Firecracker VMs that restore from memory snapshots in milliseconds, fork a running…

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

FPGA based microcomputer sandbox for software and RTL experimentation


A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Zero-trust sandbox for AI agents with kernel-level filesystem jail, transparent network proxy, and YAML-based policy engine to intercept and control…

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…