







A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.
fencesandbox/fence
Lightweight, container-free sandbox for running commands with network and filesystem restrictions
Sprites - Stateful sandboxes
Persistent, hardware-isolated execution environments for arbitrary code. Run AI agents, untrusted code, and more in secure sandbox environments with checkpoint & restore.
Vercel Sandbox
Vercel Sandbox allows you to run arbitrary code in isolated, ephemeral Linux VMs.
Moving Beyond Containers - Introducing Boxer by Daniel Phillips @Wasm I/O 2025
agentOS — A faster, lighter, cheaper alternative to sandboxes
A portable open-source operating system for agents. Stateful runtime, universal agent interface, and secure code execution. One SDK, deploy anywhere.

Dancing mad with sandboxing
Kefka is a Go-native shell sandbox with coreutils, Python via WebAssembly, and more. Learn the works of madness that went into making this happen!

libkrun/libkrun
A dynamic library providing Virtualization-based process isolation capabilities
Composable, fast, and secure dev environments | Workshop | Ubuntu
Launch agent-ready, sandboxed development environments with a single command. Define them via simple YAML configs, share them to recreate on different machines.

microsandbox - Every agent deserves its own machine
Run lightweight microVMs locally. Programmable networking, custom filesystems, secrets that never leak.
mokeyish/obsidian-code-emitter
An obsidian plugin that allows code blocks executed interactively in sandbox like jupyter notebooks. Supported language rust、kotlin、python、Javascript、TypeScript etc.
The Industry-Leading Container Runtime | Docker
Read about our industry-leading Docker container runtimes. Docker Engine allows containerized apps to run consistently on any infrastructure — from anywhere.

Container Use for Locally Sandboxed, Background Agents in Zed
From the Zed Blog: Run AI agents in parallel without interference using containerized environments and Git Worktrees.

Introducing Deno Sandbox | Deno
Instant Linux microVMs with defense-in-depth security for running untrusted code.

Genode - Genode Operating System Framework
We understand the complexity of code and policy as the most fundamental security problem shared by modern general-purpose operating systems. Because of high functional demands and dynamic workloads, however, this complexity cannot be avoided. But it can be organized. Genode is a novel OS architecture that is able to master complexity by applying a strict organizational structure to all software components including device drivers, system services, and applications. The Genode OS framework is an open-source tool kit for building highly secure component-based operating systems. It scales from embedded devices to dynamic general-purpose computing.