claudebox
Run Claude Code with a reduced-access sandbox
- Stars
- 51
- Forks
- 9
- Updated
- Updated Jun 28, 2026
Run Claude Code with a reduced-access sandbox
claudebox launches a Claude Code project through bubblewrap on Linux or sandbox-exec on macOS. It shadows most of the home directory, mounts the project parent read-only, and blocks sensitive runtime sockets by default, with opt-in SSH, GPG, and XDG access. The project explicitly says this is not a complete security boundary; Linux is stable and macOS experimental.
Resource types
Use cases
Run supported always-on AI agents inside managed NVIDIA OpenShell sandboxes.
Plan and run authorized penetration tests with autonomous agents in an isolated environment.
Platforms
Operating systems
Runtime
Protocols & integrations
Capabilities
Audience
Public GitHub facts last synced Jul 10, 2026.
Scan agent skills for malicious instructions, unsafe code, and supply-chain risks
Run a security-focused personal AI assistant on your own machine or server.