Project overview
claudebox launches a Claude Code project through bubblewrap on Linux or sandbox-exec on macOS. It shadows most of the home directory, mounts the project parent read-only, and blocks sensitive runtime sockets by default, with opt-in SSH, GPG, and XDG access. The project explicitly says this is not a complete security boundary; Linux is stable and macOS experimental.
Repository facts
- Primary language
- JavaScript
- License
- Not publicly identified
- Repository updated
- Jun 28, 2026
- Default branch
- main
Resource types
Scaffold or starterAgent harnessCLI app
Use cases
Security and privacyAI and agent developmentDevOps and deploymentSoftware development
Platforms
Claude Code
Operating systems
LinuxmacOS
Runtime
Command lineDockerLocalSandboxed
Protocols & integrations
CLI integration
Capabilities
Code executionFile operationsSecurity guardrailTool use
Audience
DevelopersSecurity engineers