Vibeleaderboard
Index / app
Visit github.com
Category
Developer Tools
Rank
No. 2054Tools index
Type
APP
Use case
Deployment & Operations · Security & Identity
Interfaces
CLI · Client SDK · MCP · Agent Skill / Plugin
Latest release
v0.7.6
Date

About

Runs untrusted workloads such as AI agent code, plugins, and CI jobs inside local microVMs with hardware-level isolation. Boots standard OCI container images in under 100 ms, embeds directly in code through Rust, Python, TypeScript, and Go SDKs, and exposes an MCP server so agents can create their own sandboxes.

What it does

Microsandbox gives each risky program its own tiny virtual machine on your own computer, so a crash or an escape attempt hits a separate kernel rather than yours. You point it at an ordinary image from Docker Hub or GitHub's registry, and it starts a guest with its own memory, CPU budget and network rules. A command-line tool covers run, exec, fork, snapshot and restore, while libraries let a program spawn a sandbox as a child process with no daemon or server to stand up first.

Why it's ranked here

Agent builders need somewhere safe to execute generated code, and this is a serious local answer. It is Apache 2.0, written as a large Rust workspace with libraries for TypeScript, Python, Go and Ruby, and it runs on macOS, Linux and Windows. The security policy names sandbox escape, egress-filter bypass and secret leakage as priority bug classes, and promises acknowledgment within three business days and a 90-day disclosure embargo. A written compatibility map spells out how new hosts must talk to old running guests. That is infrastructure discipline, not a weekend demo.

What's good

Secrets are injected on the host side and scoped to a named destination, so an API key can reach one approved host without ever existing inside the guest. Network policy has three plain presets, public internet only, allow everything, or nothing at all, plus allow lists by domain or address range. Live sandboxes can be forked into independent copies, and full snapshots can be saved to a file and restored later, optionally sharing unchanged memory. A single YAML file can set the image, memory, allowed hosts and named scripts, which keeps a sandbox reproducible.

Tradeoffs

The README calls it beta software and warns of breaking changes, missing features and rough edges. Mac support is Apple Silicon only. Linux needs KVM enabled and Windows needs the Windows Hypervisor Platform turned on, so hosts without hardware virtualization are out. The internal crates are pinned to one exact shared version because they share unstable private APIs, which signals that the internals still move. The surface is large, with a managed config layer, backend profiles and a cloud mode, so there is a lot to learn.

How to use it well

Reach for it when an agent, plugin system or CI job must run code you did not write and a container's shared kernel is not enough. Start with the command-line tool on a laptop, then move to the library in your language once the image and network policy are settled. Default to no network or public-only egress, and hand credentials over through host-side secrets bound to one host. On shared machines, set the multi-tenant deployment profile in the global config so individual sandboxes cannot weaken isolation. It is no help on hosts that lack virtualization support.

Technical notes+

Cargo.toml defines a Rust 2024 workspace with crates for agentd, cli, db, filesystem, image, runtime, network, protocol and vsock, plus SDKs under sdk/node-ts, sdk/python and sdk/go/native; internal crates use exact = version pins and the VMM comes from msb_krun. crates/runtime/lib/lib.rs splits a client feature (launch, IPC and control contracts for SDKs) from a runner feature (VM, relay, metrics, policy). crates/network/lib/lib.rs gates an engine feature with a smoltcp netstack, DNS interception, TLS interception and port publishing, and exposes SOCKS5 and HTTP CONNECT outbound proxies. COMPATIBILITY.md describes a length-prefixed CBOR agent protocol over a libkrun virtio console with generation negotiation. sdk/node-ts/src/index.ts wraps napi-rs native builders. docs/configuration.mdx documents a per-user global config file layered under an administrator-managed override file that takes precedence.

Observed

License
Apache-2.0 (LICENSE file and workspace manifest)
Primary language
Rust workspace, edition 2024
SDK languages
TypeScript, Rust, Python, Go, Ruby
Install surface
Shell installer, PowerShell installer, Homebrew tap, npm, uv, cargo
Interfaces
CLI plus embeddable library SDKs; README links a separate MCP server repository
Platform support
macOS on Apple Silicon, Linux with KVM, Windows with WHP
Isolation model
Per-sandbox microVM via libkrun, booting OCI images
Security policy
SECURITY.md with private reporting and default 90-day coordinated disclosure embargo
Compatibility documentation
COMPATIBILITY.md maps host-to-guest protocol and on-disk format boundaries

Read from README.md, Cargo.toml, LICENSE, SECURITY.md, COMPATIBILITY.md, crates/runtime/lib/lib.rs, crates/network/lib/lib.rs, crates/cli/lib/lib.rs, sdk/node-ts/src/index.ts, examples/typescript/net-policy/main.ts, docs/configuration.mdx.

Tags

ai-agentsdockergolanglinuxlocalmacosmicrovmnodejspythonrust

Tech Stack

Rust

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.