
ephemora-cell
Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

Secure and fast microVMs for serverless computing.

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

Sandbox untrusted code with safe access to the host.

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Ultrafast CLI on Apple Silicon macOS for fast, sandboxed development and LLM agents.

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

Domain-specific language for writing fast functional device models for virtual platforms. Compiles DML to C with API calls tailored for the Intel…

Run untrusted AI code safely, fast

A fuzzer for full VM kernel/driver targets