AI Dev Impact Lab JA
← Topics ranking · 2026-08
GITHUB TOPIC

#sandbox

GitHub repositories that have self-applied the topic "sandbox" — a creator-tagged metadata that surfaces how AI projects describe themselves.

31
tagged repos
1,363
top 31 stars
19
with tool sigs
31
shown

REPOS Repos for #sandbox (top 31 by stars)

LiteLLM-Labs/litellm-agent-control-plane

1 place to call all your agents - OpenCode, Hermes, Claude Managed Agents, Cursor Agents API, DeepAgents.

Rust 1,223 AI 100 1 sig live ↗
cocoonstack/sandbox

Fast cold-boot MicroVM sandboxes for AI agents on cocoon

Go 43 AI 70 live ↗
madarco/agentbox-herdr-plugin

Run multiple agents in parallel sandboxed VMs, with a single command, on your PC or in the cloud

Shell 26 AI 45 Solo live ↗
stefanoginella/aicontainer

Sandboxed devcontainer for running Claude Code, Codex, and OpenCode in bypass / auto-approve mode.

Shell 18 AI 100 Solo 2 sig live ↗
denn-gubsky/loomcycle

The runtime substrate for agentic systems — one Go binary, six LLM providers, MCP-native, configurable as a managed sandbox or full agentic dev environment. Where agents live, talk, and learn.

Go 13 AI 70 Solo 1 sig live ↗
100yenadmin/boardstate

Your dashboard is data. Any AI can build it; any human can edit it. A protocol + runtime for agent-composable dashboards — layout-as-data, one guarded control plane, sandboxed agent-authored widgets, MCP server included.

TypeScript 9 AI 70 Solo 2 sig live ↗
entropy-om/entheai

A quantum prompt playground & macOS-native Rust coding agent: morphing fluid entropy into rigid execution checkpoints. Entropy cannot lie.

Rust 6 AI 100 2 sig live ↗
onur-tellioglu/git-craft

An open, community- and AI-agent-driven Minecraft-style voxel engine in Rust on wgpu.

Rust 4 AI 70 2 sig
IvanSkainet/arena-agent

Skainet Bridge — local automation bridge for AI agents: one process, one port. MCP server + client, REST, browser extension, sandboxed exec. Independent project, unaffiliated.

Python 3 AI 100 Solo 1 sig live ↗
wzslr321/torio

Run an AI second brain and your repositories on a Linux VM you control. One Go binary: no daemon, no credentials, and a backend that cannot push.

Go 3 AI 70 Solo 2 sig live ↗
me1iissa/isopod

Firecracker-microVM sandbox for Claude Code: ephemeral hardware-isolated runs (~0.4s boot) + content-addressed environment stages, as MCP tools and a CLI

Rust 3 AI 70 Solo 1 sig live ↗
ionalpha/flynn

A sandboxed, full-featured agent operating system in a single Go binary. Bring any model, manage local models, point it at a goal, and grant it real authority: every action is sandboxed, governed, and sealed into a verifiable, tamper-evident record an independent party can check. Runs interactive or 24/7, or embed it in your own system.

Go 2 AI 70 1 sig live ↗
ElcanoTek/fleet

A general-purpose agent fleet you run yourself — any model, in a sandbox, on a budget, connected to your data.

Go 2 AI 70 2 sig live ↗
karurikwao/runwitness

Autonomous agents with receipts.

TypeScript 2 AI 45 Solo live ↗
DiogoF-Hub/claude-code-wsl-sandbox

Run Claude Code on Windows inside a real Linux sandbox. WSL 2 + ai-jail (bubblewrap, Landlock, seccomp) so the agent can only touch your project, with SSH commit signing still backed by Bitwarden.

1 AI 100 1 sig
atuljha-tech/SENTINEL

AI security layer for the agentic internet — sandbox isolation, Civic governance, and a one-API-call clearance system for any OKX.AI agent.

TypeScript 1 AI 70 Solo live ↗
lao-tseu-is-alive/Talunor

Talunor is a local-first terminal AI agent written in Go, with persistent, auditable SQLite memory, guarded tool use, and a complete step-by-step course explaining how it is built.

Go 1 AI 70 2 sig
Mindpool-Labs/ne-enclave

Confidential AI agent runtime — hardware-attested, governed sandboxes (AMD SEV-SNP). Apache-2.0. Rust top-to-bottom.

Rust 1 AI 70 live ↗
iFurySt/managed-agents

🧩 Open-source control plane for running AI agents in secure, observable sandboxes.

TypeScript 1 AI 70 2 sig
vu1n/pillbox

Durable coding-agent sessions on Cloudflare, with sovereign local libkrun microVM handoffs.

Rust 1 AI 70 2 sig
kruxshnx/coding-agent

Autonomous coding agent that fixes buggy repos by iterating against their pytest suite in an isolated Docker sandbox provider-agnostic LLM layer, 22-task eval harness, and OpenTelemetry→Langfuse tracing.

Python 0 AI 100
otaviosoaresp/claude-sandbox

Run Claude Code with --dangerously-skip-permissions inside a container with no route to your host and SNI-filtered egress

Shell 0 AI 100
Enigma-Technologies-Solutions/sanctum

Run AI-generated HTML tools in an isolated sandbox. Static capability scanning, per-tool origin isolation, dynamic CSP enforcement.

TypeScript 0 AI 70 live ↗
domestof/open-mobile-session

Claude Code skill: safely spawn a sandboxed, phone-drivable Remote Control session

0 AI 70 Solo live ↗
api-evangelist/anchorbrowser

Anchor Browser is an AI-native cloud browser infrastructure platform that lets AI agents interact with the web the same way a human would. It provides hosted, isolated Chromium sessions ("Anchor Chromium"), built-in stealth and bot-evasion tuning, an authentication layer (OmniConnect) for managing logged-in user credentials, a built-in enterprise…

0 AI 70
wangxing-git/dsh-autogate

DeepSeek Harness 自动审批插件:在 workspace-write 沙箱之上叠加确定性规则 + LLM 安全审批,自动模式不放宽沙箱、fail-closed。 Safe auto-approval for DeepSeek Harness — deterministic rules + LLM review on top of the workspace-write sandbox. Auto mode without ever granting full-access.

TypeScript 0 AI 70 1 sig
yoichiojima-2/syros

Run Claude Agent SDK agents in sandboxed Cloud Run Jobs inside your own GCP project — audit trails, human approval gates, agents, scheduled deployments, platform connectors, Agent Skills, and zero always-on cost

Python 0 AI 70 1 sig
pamin-labs/orchestrator

An AI team for a company of one. You do three things: say what you want, approve the plan, merge the PR. Nine roles do the rest — planning, building, reviewing it twice — each inside its own container, so if an agent runs rm -rf it happens to a container, not to you.

TypeScript 0 AI 70 2 sig
levmv/skot

Terminal agent with durable sessions and background jobs, a fail-closed filesystem sandbox, and first-class unattended runs. Written in Go.

Go 0 AI 70
rbardyla-boop/claude_powerplant

Trust-bounded acceptance harness for Claude coding agents — sanitized workspaces, typed tools, isolated oracle evaluation, evidence receipts.

TypeScript 0 AI 60 1 sig
agent-of-mkmeral/strands-bubblewrap

Bubblewrap (bwrap) sandbox for Strands Agents — unprivileged Linux user-namespace command/code execution.

Python 0 AI 45 Solo live ↗

RELATED Other topics · full topics ranking →

#claude-code

1,555

#ai-agents

1,156

#llm

1,066

#claude

936

#python

802

#ai

737

#developer-tools

723

#mcp

719

#codex

517

Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology