Back to browse
Userland local agent sandbox with real-time network control dashboard

Userland local agent sandbox with real-time network control dashboard

by cowpig·Mar 13, 2026·7 points·1 comment

AI Analysis

●●●BangerWizardrySolve My ProblemZero to One

Kernel-enforced agent sandboxing that blocks .env access without container overhead.

Strengths
  • macOS Seatbelt profiles generated per-session with default-deny filesystem policies.
  • Real-time dashboard shows every outbound connection with allow/deny controls.
  • Works with any agent (Claude Code, Cursor, Aider) without agent-specific config.
Weaknesses
  • Linux implementation relies on proxy-based network control vs macOS native Seatbelt.
  • Requires understanding kernel sandbox concepts to customize policies effectively.
Category
Target Audience

Developers running AI coding agents locally

Similar To

Firecracker · gVisor · Bubblewrap

Similar Projects

Security●●●Banger

Hazmat – I made unrestricted Claude Code safe on macOS

TLA+ verified sandbox makes --dangerously-skip-permissions safe for Claude Code and other agents on macOS.

WizardrySolve My ProblemShip It
dredozubov
112mo ago