agent-sandbox
mattolson/agent-sandbox
Agent Sandbox provides a secure local environment utilizing Docker containers and a sidecar proxy to safely run AI coding agents with restricted network and filesystem access.
Overview
This tool creates a locked-down execution environment specifically designed for autonomous AI coding agents. It limits filesystem exposure strictly to the designated repository and routes all outbound network traffic through an enforcing proxy sidecar, preventing unauthorized data exfiltration or unmonitored API calls while injecting required authentication secrets safely.
Capabilities
- ▸Containerized isolation for AI coding agents
- ▸Sidecar proxy with fine-grained egress filtering by hostname, method, and path
- ▸Secret injection managed via the proxy layer rather than exposed inside the container
- ▸Iptables firewall blocking direct outbound traffic
- ▸Persistent volume mounting for agent auth and state preservation
- ▸Support for both CLI execution and IDE devcontainers (VS Code, JetBrains)
Best for
Running third-party AI coding agents safely on sensitive codebases, Restricting agent network access to specific approved hostnames and endpoints, Isolating AI code execution via containerized Debian environments and Docker Compose
Works with
実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 — AIによるcapabilities/use-cases解析
実装・指示の品質。 — AIによるSKILL.md/README解析
リポジトリがどれだけ活発に保守されているか。 — GitHub 最終push日時の新しさ
ドキュメントの充実度・分かりやすさ。 — README/独自要約の情報量
危険・不審な挙動が無いか。 — AIによるセキュリティレビュー
ありふれたラッパーではない独自性。 — AIによる独自性判定
コミュニティの採用度。 — GitHub Stars/Forks(対数スケール)
対応AIエージェントの広さ。 — AIによる対応エージェント判定
ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →
Security considerations
The skill relies on a robust combination of iptables rules inside the container and a python-based mitmproxy sidecar to enforce network constraints. Secrets are injected at the proxy layer so that the running agent container never holds raw API credentials.
Categories
Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.