anthropics

sandbox-runtime: Restrict Process Access Without Containers

Anthropic Sandbox Runtime wraps processes with OS-enforced filesystem and network restrictions, aimed especially at AI agents and MCP servers. It is actively maintained, but remains a beta research preview with platform-specific setup and limitations.

ActiveTypeScriptApache-2.0SecurityCLIAI Agents
Stars
5.5k
Forks
481
Last commit
today
Contributors
36
Releases, 12 months
42

Our take

Activeregular commits and releases
  • Merges more pull requests than 89% of the projects we track
  • Releases more often than 85% of the projects we track

This is a promising, actively developed process-sandboxing toolkit for agent and developer workflows, with a broad platform scope that calls for careful validation before production adoption.

Good fit if

  • You need OS-enforced restrictions around local commands, agents, or MCP servers without requiring a container.
  • You can configure access explicitly and account for platform-specific behavior and dependencies.
  • You want a TypeScript integration under the Apache-2.0 license, and can work with a beta research preview.

Look elsewhere if

  • You need a mature, stable interface: the project identifies itself as a research preview and says APIs and configuration may evolve.
  • You need Windows support at the same maturity as the other platforms, since Windows is alpha.
  • Your environment cannot meet the Node.js requirement or install the required Linux or macOS utilities.
All health signals
Last commit2026-10-10 (today)
Commits, last 90 days100+
Releases, last 12 months42 (latest v0.0.79, 2026-10-07)
Contributors36 (top contributor: 17% of commits)
Issues closed, last 90 days3+ (typically closed in 8 days)
Pull requests merged, last 90 days82 (typically merged in 2 days)
Project age12 months

Checked on 2026-10-10 with the GitHub API.

Overview

Anthropic Sandbox Runtime (srt) is a CLI and TypeScript library for running a process with restricted filesystem and network access. It uses operating-system sandboxing rather than requiring a container, and applies restrictions to the wrapped process and its child processes.

It is designed for teams that need to limit what an agent, MCP server, or other local command can read, change, or reach over the network. Access starts restricted for writes and network connections, with configuration to allow specific paths and destinations.

Key Features

  • Restricts filesystem reads and writes using configurable allow and deny rules.
  • Mediates HTTP, HTTPS, and other TCP traffic through proxies with domain rules.
  • Provides Unix socket controls, with platform-specific behavior.
  • Supports macOS and Linux OS-level sandboxing, plus alpha Windows support using a dedicated local account and Windows security controls.
  • Offers both an srt command-line wrapper and a TypeScript library API.
  • Records sandbox violations, with additional real-time violation monitoring on macOS.
  • Can wrap MCP servers and other arbitrary processes, including their child processes.

Use Cases

  • AI agent developers can limit an agent's shell commands to workspace files and explicitly approved network destinations.
  • MCP server operators can restrict a server's filesystem access, such as blocking writes to sensitive directories.
  • Developer tooling teams can run scripts or package commands with narrower filesystem and network permissions than the host user has.
  • Library integrators can add sandbox wrapping and violation attribution to a TypeScript application that launches processes.

What you need

Detected in the repository

  • Node.js >=22.12.0 (from package.json)
  • A test suite and automated checks on GitHub Actions

License in plain words

Apache-2.0permissive

  • Commercial use: yes
  • Modify and redistribute: yes
  • You must keep: the license, the NOTICE file and a note of your changes
  • Share your changes: no
  • Includes an explicit patent grant from the contributors:

A summary, not legal advice: the LICENSE file is what applies.

Getting Started

Install the CLI with npm:

npm install -g @anthropic-ai/sandbox-runtime

Then wrap a command, for example srt echo "hello world". See the README for configuration, platform setup, and library usage.

Alternatives

  • gh-aw-firewall: gh-aw-firewall runs workflow commands in Docker with approved-domain network limits and credential isolation, rather than applying OS-level filesystem and network restrictions to processes.
  • microsandbox: Microsandbox isolates untrusted code in disposable local microVMs, rather than wrapping host processes with OS-enforced filesystem and network restrictions.
ProjectLanguageLicenseStarsStatus
sandbox-runtimeTypeScriptApache-2.05.5kActive
gh-aw-firewallTypeScriptMIT150Active
microsandboxRustApache-2.08.5kActive

Considerations

The project is a beta research preview, so teams should expect configuration and APIs to change. Development is active, with regular commits and releases, and contributions from dozens of people rather than dependence on one contributor. Recent issue closure has been limited, though the reported median time to close is about a week; pull requests have generally been merged quickly.

Platform support is not uniform. Linux needs bubblewrap, socat, and ripgrep, macOS needs ripgrep, and Windows requires a one-time elevated installation and is explicitly alpha. The README also documents edge cases in filesystem glob handling and differences between platform sandbox mechanisms, so test the exact restrictions your workload depends on.

Found this useful?

Share it with someone who would like sandbox-runtime.

OS
OSRepos

Analysis and discovery of open source repositories. Find interesting projects and follow their updates.

Monitor your website with YourWebsiteScore

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of third-party repository code is at your own risk. Always review source code, dependencies, licenses, and security implications before running anything.

© 2025 OSRepos. Built with Nuxt 3 and lots of ❤️