# sandbox-runtime: Restrict Process Access Without Containers

This repository profile is provided by osrepos.com, an open source repository discovery platform.

Source: osrepos.com
Repository profile: https://osrepos.com/repo/anthropics-sandbox-runtime
Generated for open source discovery and AI-assisted research.

Anthropic Sandbox Runtime wraps processes with OS-enforced filesystem and network restrictions, aimed especially at AI agents and MCP servers. It is actively maintained, but remains a beta research preview with platform-specific setup and limitations.

GitHub: https://github.com/anthropics/sandbox-runtime
OSRepos URL: https://osrepos.com/repo/anthropics-sandbox-runtime

## Summary

Anthropic Sandbox Runtime wraps processes with OS-enforced filesystem and network restrictions, aimed especially at AI agents and MCP servers. It is actively maintained, but remains a beta research preview with platform-specific setup and limitations.

## Topics

- typescript
- security
- cli
- ai-agents
- process-sandbox
- network-filtering
- filesystem-restrictions

## Repository Information

Last analyzed by OSRepos: Sat Oct 10 2026 17:28:23 GMT+0100 (Western European Summer Time)
Detail views: 1
GitHub clicks: 0

## Safety Notice

OSRepos shares public repositories for knowledge and discovery only. Review source code, dependencies, licenses, and security implications before running or installing anything.

## Content

## Overview

Anthropic Sandbox Runtime (`srt`) is a CLI and TypeScript library for running a process with restricted filesystem and network access. It uses operating-system sandboxing rather than requiring a container, and applies restrictions to the wrapped process and its child processes.

It is designed for teams that need to limit what an agent, MCP server, or other local command can read, change, or reach over the network. Access starts restricted for writes and network connections, with configuration to allow specific paths and destinations.

## Key Features

- Restricts filesystem reads and writes using configurable allow and deny rules.
- Mediates HTTP, HTTPS, and other TCP traffic through proxies with domain rules.
- Provides Unix socket controls, with platform-specific behavior.
- Supports macOS and Linux OS-level sandboxing, plus alpha Windows support using a dedicated local account and Windows security controls.
- Offers both an `srt` command-line wrapper and a TypeScript library API.
- Records sandbox violations, with additional real-time violation monitoring on macOS.
- Can wrap MCP servers and other arbitrary processes, including their child processes.

## Use Cases

- **AI agent developers** can limit an agent's shell commands to workspace files and explicitly approved network destinations.
- **MCP server operators** can restrict a server's filesystem access, such as blocking writes to sensitive directories.
- **Developer tooling teams** can run scripts or package commands with narrower filesystem and network permissions than the host user has.
- **Library integrators** can add sandbox wrapping and violation attribution to a TypeScript application that launches processes.

## Our Take

This is a promising, actively developed process-sandboxing toolkit for agent and developer workflows, with a broad platform scope that calls for careful validation before production adoption.

**Good fit if:**
- You need OS-enforced restrictions around local commands, agents, or MCP servers without requiring a container.
- You can configure access explicitly and account for platform-specific behavior and dependencies.
- You want a TypeScript integration under the Apache-2.0 license, and can work with a beta research preview.

**Look elsewhere if:**
- You need a mature, stable interface: the project identifies itself as a research preview and says APIs and configuration may evolve.
- You need Windows support at the same maturity as the other platforms, since Windows is alpha.
- Your environment cannot meet the Node.js requirement or install the required Linux or macOS utilities.

## Project Health

| Signal | Value |
|---|---|
| Status | **Active**: regular commits and releases |
| Last commit | 2026-10-10 (today) |
| Commits, last 90 days | 100+ |
| Releases, last 12 months | 42 (latest v0.0.79, 2026-10-07) |
| Contributors | 36 (top contributor: 17% of commits) |
| Issues closed, last 90 days | 3+ (typically closed in 8 days) |
| Pull requests merged, last 90 days | 82 (typically merged in 2 days) |
| Project age | 12 months |

Checked on 2026-10-10 with the GitHub API.

## Project Facts

- Language: TypeScript
- License: Apache-2.0
- Stars: 5.5k
- Forks: 481
- Archived: no

## What You Need

Detected in the repository:

- Node.js >=22.12.0 (from package.json)
- A test suite and automated checks on GitHub Actions

## Getting Started

Install the CLI with npm:

```bash
npm install -g @anthropic-ai/sandbox-runtime
```

Then wrap a command, for example `srt echo "hello world"`. See the [README](https://github.com/anthropics/sandbox-runtime#readme) for configuration, platform setup, and library usage.

## License in Plain Words

**Apache-2.0** (permissive).

- Commercial use: yes
- Modify and redistribute: yes
- You must keep: the license, the NOTICE file and a note of your changes
- Share your changes: no
- Includes an explicit patent grant from the contributors

A summary, not legal advice: the LICENSE file is what applies.

## Alternatives

- [gh-aw-firewall](https://osrepos.com/repo/github-gh-aw-firewall): gh-aw-firewall runs workflow commands in Docker with approved-domain network limits and credential isolation, rather than applying OS-level filesystem and network restrictions to processes.
- [microsandbox](https://osrepos.com/repo/microsandbox-microsandbox): Microsandbox isolates untrusted code in disposable local microVMs, rather than wrapping host processes with OS-enforced filesystem and network restrictions.

| Project | Language | License | Stars | Status |
|---|---|---|---|---|
| **sandbox-runtime** | TypeScript | Apache-2.0 | 5.5k | Active |
| [gh-aw-firewall](https://osrepos.com/repo/github-gh-aw-firewall) | TypeScript | MIT | 150 | Active |
| [microsandbox](https://osrepos.com/repo/microsandbox-microsandbox) | Rust | Apache-2.0 | 8.5k | Active |

## Considerations

The project is a beta research preview, so teams should expect configuration and APIs to change. Development is active, with regular commits and releases, and contributions from dozens of people rather than dependence on one contributor. Recent issue closure has been limited, though the reported median time to close is about a week; pull requests have generally been merged quickly.

Platform support is not uniform. Linux needs bubblewrap, socat, and ripgrep, macOS needs ripgrep, and Windows requires a one-time elevated installation and is explicitly alpha. The README also documents edge cases in filesystem glob handling and differences between platform sandbox mechanisms, so test the exact restrictions your workload depends on.