
matchlock
Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

Scripts to build Kali cloud images (fork of https://salsa.debian.org/cloud-team/debian-cloud-images)

A secure low code deception runtime framework, leveraging AI for System Virtualization.

A lightweight command sandbox for Linux, secure-by-default, built on Landlock.

Let your AI go full send. Your home directory stays home.

Go Trusted Execution Environment (TEE)

The fastest LoongArch sandbox

GoTEE - example application

Domain-specific language for writing fast functional device models for virtual platforms. Compiles DML to C with API calls tailored for the Intel…

ArmourBird CSF - Container Security Framework

Manages the core lifecycle of Qubes OS domains via a Python admin API, handling secure compartmentalization with Xen and exposing an event system for…

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

Immutable Linux OS image optimized for running Incus containers and virtual machines, with UEFI Secure Boot, TPM 2.0 disk encryption, and automated…

Benchmark for evaluating AI agents on real-world tasks including vulnerability resolution, code debugging, and protein assembly in containerized…

Easily create full virtual machines that are sandboxed for development or computer use models.

A PS5 hypervisor exploit for 1.xx-2xx firmwares.

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…