sandlock
View on GitHubThe lightest AI sandbox. A process-based sandbox for Linux, no container, no VM, no privilege, no prompt injection
A Linux process sandbox for running untrusted code, including AI agent workloads. It uses Landlock and seccomp for filesystem, network, and syscall controls, with Rust, Python, and Go interfaces.
Use Cases
Run AI-generated code with restricted filesystem and network accessEnforce HTTP host, method, and path allowlists for agent trafficLimit memory, processes, and execution time without containersInspect or discard filesystem changes from sandboxed runs
Built With
- Language
- Rust
Tags
AI agent sandbox · process isolation · Linux · Landlock · seccomp · network controls · filesystem isolation · prompt injection defense · untrusted code