{"name":"sandbox-runtime: Restrict Process Access Without Containers","description":"Anthropic Sandbox Runtime wraps processes with OS-enforced filesystem and network restrictions, aimed especially at AI agents and MCP servers. It is actively maintained, but remains a beta research preview with platform-specific setup and limitations.","github":"https://github.com/anthropics/sandbox-runtime","url":"https://osrepos.com/repo/anthropics-sandbox-runtime","source":"osrepos.com","sourceDescription":"This repository profile is provided by osrepos.com, an open source repository discovery platform.","repositoryProfile":"https://osrepos.com/repo/anthropics-sandbox-runtime","generatedFor":"open source discovery and AI-assisted research","markdown":"https://osrepos.com/repo/anthropics-sandbox-runtime.md","json":"https://osrepos.com/repo/anthropics-sandbox-runtime.json","topics":["typescript","security","cli","ai-agents","process-sandbox","network-filtering","filesystem-restrictions"],"keywords":["typescript","security","cli","ai-agents","process-sandbox","network-filtering","filesystem-restrictions"],"stars":null,"summary":"Anthropic Sandbox Runtime wraps processes with OS-enforced filesystem and network restrictions, aimed especially at AI agents and MCP servers. It is actively maintained, but remains a beta research preview with platform-specific setup and limitations.","content":"## Overview\n\nAnthropic Sandbox Runtime (`srt`) is a CLI and TypeScript library for running a process with restricted filesystem and network access. It uses operating-system sandboxing rather than requiring a container, and applies restrictions to the wrapped process and its child processes.\n\nIt is designed for teams that need to limit what an agent, MCP server, or other local command can read, change, or reach over the network. Access starts restricted for writes and network connections, with configuration to allow specific paths and destinations.\n\n## Key Features\n\n- Restricts filesystem reads and writes using configurable allow and deny rules.\n- Mediates HTTP, HTTPS, and other TCP traffic through proxies with domain rules.\n- Provides Unix socket controls, with platform-specific behavior.\n- Supports macOS and Linux OS-level sandboxing, plus alpha Windows support using a dedicated local account and Windows security controls.\n- Offers both an `srt` command-line wrapper and a TypeScript library API.\n- Records sandbox violations, with additional real-time violation monitoring on macOS.\n- Can wrap MCP servers and other arbitrary processes, including their child processes.\n\n## Use Cases\n\n- **AI agent developers** can limit an agent's shell commands to workspace files and explicitly approved network destinations.\n- **MCP server operators** can restrict a server's filesystem access, such as blocking writes to sensitive directories.\n- **Developer tooling teams** can run scripts or package commands with narrower filesystem and network permissions than the host user has.\n- **Library integrators** can add sandbox wrapping and violation attribution to a TypeScript application that launches processes.\n\n## Our Take\n\nThis is a promising, actively developed process-sandboxing toolkit for agent and developer workflows, with a broad platform scope that calls for careful validation before production adoption.\n\n**Good fit if:**\n- You need OS-enforced restrictions around local commands, agents, or MCP servers without requiring a container.\n- You can configure access explicitly and account for platform-specific behavior and dependencies.\n- You want a TypeScript integration under the Apache-2.0 license, and can work with a beta research preview.\n\n**Look elsewhere if:**\n- You need a mature, stable interface: the project identifies itself as a research preview and says APIs and configuration may evolve.\n- You need Windows support at the same maturity as the other platforms, since Windows is alpha.\n- Your environment cannot meet the Node.js requirement or install the required Linux or macOS utilities.\n\n## Project Health\n\n| Signal | Value |\n|---|---|\n| Status | **Active**: regular commits and releases |\n| Last commit | 2026-10-10 (today) |\n| Commits, last 90 days | 100+ |\n| Releases, last 12 months | 42 (latest v0.0.79, 2026-10-07) |\n| Contributors | 36 (top contributor: 17% of commits) |\n| Issues closed, last 90 days | 3+ (typically closed in 8 days) |\n| Pull requests merged, last 90 days | 82 (typically merged in 2 days) |\n| Project age | 12 months |\n\nChecked on 2026-10-10 with the GitHub API.\n\n## Project Facts\n\n- Language: TypeScript\n- License: Apache-2.0\n- Stars: 5.5k\n- Forks: 481\n- Archived: no\n\n## What You Need\n\nDetected in the repository:\n\n- Node.js >=22.12.0 (from package.json)\n- A test suite and automated checks on GitHub Actions\n\n## Getting Started\n\nInstall the CLI with npm:\n\n```bash\nnpm install -g @anthropic-ai/sandbox-runtime\n```\n\nThen wrap a command, for example `srt echo \"hello world\"`. See the [README](https://github.com/anthropics/sandbox-runtime#readme) for configuration, platform setup, and library usage.\n\n## License in Plain Words\n\n**Apache-2.0** (permissive).\n\n- Commercial use: yes\n- Modify and redistribute: yes\n- You must keep: the license, the NOTICE file and a note of your changes\n- Share your changes: no\n- Includes an explicit patent grant from the contributors\n\nA summary, not legal advice: the LICENSE file is what applies.\n\n## Alternatives\n\n- [gh-aw-firewall](https://osrepos.com/repo/github-gh-aw-firewall): gh-aw-firewall runs workflow commands in Docker with approved-domain network limits and credential isolation, rather than applying OS-level filesystem and network restrictions to processes.\n- [microsandbox](https://osrepos.com/repo/microsandbox-microsandbox): Microsandbox isolates untrusted code in disposable local microVMs, rather than wrapping host processes with OS-enforced filesystem and network restrictions.\n\n| Project | Language | License | Stars | Status |\n|---|---|---|---|---|\n| **sandbox-runtime** | TypeScript | Apache-2.0 | 5.5k | Active |\n| [gh-aw-firewall](https://osrepos.com/repo/github-gh-aw-firewall) | TypeScript | MIT | 150 | Active |\n| [microsandbox](https://osrepos.com/repo/microsandbox-microsandbox) | Rust | Apache-2.0 | 8.5k | Active |\n\n## Considerations\n\nThe project is a beta research preview, so teams should expect configuration and APIs to change. Development is active, with regular commits and releases, and contributions from dozens of people rather than dependence on one contributor. Recent issue closure has been limited, though the reported median time to close is about a week; pull requests have generally been merged quickly.\n\nPlatform support is not uniform. Linux needs bubblewrap, socat, and ripgrep, macOS needs ripgrep, and Windows requires a one-time elevated installation and is explicitly alpha. The README also documents edge cases in filesystem glob handling and differences between platform sandbox mechanisms, so test the exact restrictions your workload depends on.","metrics":{"detailViews":1,"githubClicks":0},"dates":{"published":null,"modified":"2026-10-10T16:28:23.000Z"}}