

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

An open-source, next-generation "runc" that empowers rootless containers to run workloads such as Systemd, Docker, Kubernetes, just like VMs.


🛡️ Windows Hello™ style facial authentication for Linux

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

A local sandbox for your AI agents

A secure low code deception runtime framework, leveraging AI for System Virtualization.

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

Framework for compiling and executing Go applications on bare metal processors, enabling secure firmware development with reduced attack surface…

Sandboxed Execution Environment

A collection of links related to VMware escape exploits

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

A Microservices-based framework for the study of Network Security and Penetration Test techniques

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

Secure code execution