Skip to content
/
§ a9

Sandbox / execution substrate

MicroVM/container/WASM runtime. Sits below the agent loop, not inside it.

13 primary frameworks · 7 lower-confidence entries

Daytona
daytona
★ 72k
Tier A

Provide secure, elastic, sub-90ms sandbox compute infrastructure for running AI-generated code, accessible via multi-language SDKs and REST API.

CUA
cua-sandbox
★ 17k
Tier A

Unified SDK for building, benchmarking, and deploying agents that interact with full OS GUIs via isolated VMs.

E2B
e2b
★ 12k
Tier A

Run AI-generated code safely in cloud-hosted isolated sandboxes via a 3-line SDK integration.

OpenSandbox
opensandbox
★ 11k
Tier A

Protocol-first general-purpose sandbox platform for AI applications with multi-language SDKs and pluggable isolation backends.

Microsandbox
microsandbox
★ 6.3k
Tier A

Spawn hardware-isolated microVMs as child processes directly from application code, with no server setup, in under 100ms.

CubeSandbox
cubesandbox
★ 5.9k
Tier A

Sub-60ms KVM microVM sandboxes for AI agents with E2B drop-in compatibility and <5MB memory overhead.

sandcastle (mattpocock)
sandcastle-mattpocock
★ 5.1k
Tier A

Container-isolated TypeScript SDK for orchestrating AI coding agents with Docker/Podman/Vercel Firecracker sandboxes and git-worktree branch management.

VoltAgent awesome-codex-subagents
voltagent-codex-subagents
★ 4.9k
Tier A

166 Codex-native TOML subagents across 13 categories with sandbox_mode isolation and smart GPT model routing.

Agent Sandbox (kubernetes-sigs)
agent-sandbox-k8s
★ 2.5k
Tier A

Provide a first-class Kubernetes CRD for singleton stateful workloads with stable identity, persistent storage, and hibernation — the missing primitive for AI…

VibeKit
vibekit
★ 1.8k
Tier A

TypeScript SDK that routes any coding agent to any sandbox backend with built-in secrets redaction, git worktree isolation, and PR creation.

Clearwing
clearwing
★ 982
Tier A

Autonomous LLM-powered vulnerability discovery with crash-validated PoCs, multi-stage model routing, and responsible disclosure tooling — open-source…

Arrakis
arrakis
★ 816
Tier A

Self-hosted MicroVM sandbox server with snapshot-and-restore for AI agent code execution, computer use (VNC/Chrome), and MCTS-style backtracking.

Capsule
capsule
★ 285
Tier A

WebAssembly-based function-level sandbox for executing untrusted Python/TypeScript code with configurable CPU, memory, timeout, and network limits.

Show 7 lower-confidence entriestier-b · tier-c · unknown · delta reports

These entries map to § a9 by tag but carry weaker evidence — fewer documented primitives, delta reports of absent skills, or marketing-only sites without a public repo. They're listed for completeness; treat them with appropriate caution.

IronClaw ★ 12k
ironclaw

WASM-sandboxed personal AI runtime with defense-in-depth security: capability-based tool isolation, credential vault, prompt injection defense, and endpoint all…

OpenShell ★ 6.3k
openshell-nvidia

Safe, policy-governed sandbox runtime for autonomous AI agents with four-layer defense-in-depth (filesystem/network/process/inference) and hot-reloadable YAML p…

agent-infra sandbox ★ 4.8k
agent-infra-sandbox

All-in-one Docker container sandbox combining Browser (VNC), Terminal, File, VSCode Server, Jupyter, and MCP in a unified environment with shared filesystem.

stakpak/agent ★ 1.6k
stakpak-agent

24/7 DevOps AI agent with dynamic secret substitution, Warden pre-execution guardrails, and Docker sandbox isolation for safe autonomous infrastructure operatio…

E2B Desktop Sandbox ★ 1.4k
e2b-desktop

Cloud-managed graphical desktop sandbox (MicroVM + VNC) for LLM Computer Use agents — create, control, and stream a real GUI environment via simple SDK.

Tensorlake ★ 926
tensorlake

Fastest Firecracker MicroVM sandbox platform with sub-second cold starts, runtime snapshots/clones, and integrated serverless fan-out orchestration for Python a…

AgentScope Runtime ★ 800
agentscope-runtime

Production runtime for exposing any Python agent as a scalable HTTP/SSE streaming service with containerized tool execution sandbox.