Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support planned.
A Rust sandbox engine for running AI agents with OS-level isolation and default-deny Dogwood policies. It controls filesystem, process, network, and MCP access, and can inject credentials without exposing secrets to the agent.
Use Cases
Run AI agents with restricted filesystem, process, and network accessEnforce default-deny policies for agent actionsBroker MCP tool calls through policy checksInject credentials into permitted requests without exposing secrets to agentsRecord policy decisions for auditing
Built With
- Language
- Rust
- Frameworks
- Strands Agents · Dogwood · MCP · OpenTelemetry
Tags
agent sandbox · AI safety · containment · zero trust · access control · egress control · credential injection · policy engine · macOS · Rust