Our take
Activeregular commits and releases- Merges more pull requests than 89% of the projects we track
- Releases more often than 85% of the projects we track
This is a promising, actively developed process-sandboxing toolkit for agent and developer workflows, with a broad platform scope that calls for careful validation before production adoption.
Good fit if
- You need OS-enforced restrictions around local commands, agents, or MCP servers without requiring a container.
- You can configure access explicitly and account for platform-specific behavior and dependencies.
- You want a TypeScript integration under the Apache-2.0 license, and can work with a beta research preview.
Look elsewhere if
- You need a mature, stable interface: the project identifies itself as a research preview and says APIs and configuration may evolve.
- You need Windows support at the same maturity as the other platforms, since Windows is alpha.
- Your environment cannot meet the Node.js requirement or install the required Linux or macOS utilities.
All health signals
| Last commit | 2026-10-10 (today) |
|---|---|
| Commits, last 90 days | 100+ |
| Releases, last 12 months | 42 (latest v0.0.79, 2026-10-07) |
| Contributors | 36 (top contributor: 17% of commits) |
| Issues closed, last 90 days | 3+ (typically closed in 8 days) |
| Pull requests merged, last 90 days | 82 (typically merged in 2 days) |
| Project age | 12 months |
Checked on 2026-10-10 with the GitHub API.
Overview
Anthropic Sandbox Runtime (srt) is a CLI and TypeScript library for running a process with restricted filesystem and network access. It uses operating-system sandboxing rather than requiring a container, and applies restrictions to the wrapped process and its child processes.
It is designed for teams that need to limit what an agent, MCP server, or other local command can read, change, or reach over the network. Access starts restricted for writes and network connections, with configuration to allow specific paths and destinations.
Key Features
- Restricts filesystem reads and writes using configurable allow and deny rules.
- Mediates HTTP, HTTPS, and other TCP traffic through proxies with domain rules.
- Provides Unix socket controls, with platform-specific behavior.
- Supports macOS and Linux OS-level sandboxing, plus alpha Windows support using a dedicated local account and Windows security controls.
- Offers both an
srtcommand-line wrapper and a TypeScript library API. - Records sandbox violations, with additional real-time violation monitoring on macOS.
- Can wrap MCP servers and other arbitrary processes, including their child processes.
Use Cases
- AI agent developers can limit an agent's shell commands to workspace files and explicitly approved network destinations.
- MCP server operators can restrict a server's filesystem access, such as blocking writes to sensitive directories.
- Developer tooling teams can run scripts or package commands with narrower filesystem and network permissions than the host user has.
- Library integrators can add sandbox wrapping and violation attribution to a TypeScript application that launches processes.
What you need
Detected in the repository
- Node.js >=22.12.0 (from package.json)
- A test suite and automated checks on GitHub Actions
License in plain words
Apache-2.0permissive
- Commercial use: yes
- Modify and redistribute: yes
- You must keep: the license, the NOTICE file and a note of your changes
- Share your changes: no
- Includes an explicit patent grant from the contributors:
A summary, not legal advice: the LICENSE file is what applies.
Getting Started
Install the CLI with npm:
npm install -g @anthropic-ai/sandbox-runtime
Then wrap a command, for example srt echo "hello world". See the README for configuration, platform setup, and library usage.
Alternatives
- gh-aw-firewall: gh-aw-firewall runs workflow commands in Docker with approved-domain network limits and credential isolation, rather than applying OS-level filesystem and network restrictions to processes.
- microsandbox: Microsandbox isolates untrusted code in disposable local microVMs, rather than wrapping host processes with OS-enforced filesystem and network restrictions.
| Project | Language | License | Stars | Status |
|---|---|---|---|---|
| sandbox-runtime | TypeScript | Apache-2.0 | 5.5k | Active |
| gh-aw-firewall | TypeScript | MIT | 150 | Active |
| microsandbox | Rust | Apache-2.0 | 8.5k | Active |
Considerations
The project is a beta research preview, so teams should expect configuration and APIs to change. Development is active, with regular commits and releases, and contributions from dozens of people rather than dependence on one contributor. Recent issue closure has been limited, though the reported median time to close is about a week; pull requests have generally been merged quickly.
Platform support is not uniform. Linux needs bubblewrap, socat, and ripgrep, macOS needs ripgrep, and Windows requires a one-time elevated installation and is explicitly alpha. The README also documents edge cases in filesystem glob handling and differences between platform sandbox mechanisms, so test the exact restrictions your workload depends on.
Found this useful?
Share it with someone who would like sandbox-runtime.