Scaffold or starterSecurity and privacy

claudebox

Run Claude Code with a reduced-access sandbox

Stars
51
Forks
9
License
Not publicly identified
Updated
Updated Jun 28, 2026

Checking live repository facts…

Project overview

claudebox launches a Claude Code project through bubblewrap on Linux or sandbox-exec on macOS. It shadows most of the home directory, mounts the project parent read-only, and blocks sensitive runtime sockets by default, with opt-in SSH, GPG, and XDG access. The project explicitly says this is not a complete security boundary; Linux is stable and macOS experimental.

Repository facts

Primary language
JavaScript
License
Not publicly identified
Repository updated
Jun 28, 2026
Default branch
main

Resource types

Scaffold or starterAgent harnessCLI app

Use cases

Security and privacyAI and agent developmentDevOps and deploymentSoftware development

Platforms

Claude Code

Operating systems

LinuxmacOS

Runtime

Command lineDockerLocalSandboxed

Protocols & integrations

CLI integration

Capabilities

Code executionFile operationsSecurity guardrailTool use

Audience

DevelopersSecurity engineers

Related projects

Browse more similar projects