MIDREAL

Home / box

strands-agents

box

WatchingWatchingNone of the above. Nothing stands out yet. More on the methodology page

strands-agents/box

Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support planned.

RustCategories: MCP

Our summary

Strands Box is an open-source sandbox engine for running AI agents with restricted access to files, programs, and network. It combines OS-level isolation with Dogwood policy rules that control what agents can execute, read, write, and reach.

Who it is for: Developers deploying AI agents who need security controls.

What the README claims

  • Supports macOS on Apple silicon with Linux support planned Box currently supports local execution on macOS with Apple silicon. Not checked
  • Uses Dogwood policies with default-deny enforcement Operations checked by the engine are denied by default: a matching `permit` must allow the operation, and a matching `forbid` overrides that permission. Not checked
  • Supports credential injection that keeps secrets outside the agent The gateway authenticates permitted requests with configured API credentials or AWS SigV4 signing. The agent does not receive the underlying secrets. Not checked
  • Records policy decisions in OTLP JSON format Box records policy decisions in OTLP JSON. By default, records go to `<box_dir>/private/telemetry/records.jsonl`. Not checked

Written by AI from the project's README on 2026-10-09. It does not affect the verdict.

Watching: no other rule matched yet.

244 stars on GitHub. Last push today.

Verdict

OVERHYPED scored 1h ago

Hype
92
Reality
33
Hype Gap
+59
Momentum
-
Confidence
60%
  • Responsive moves Reality -7 points.
  • Maintained moves Reality -7 points.
  • No package or download data found; verdict based on activity only.

Rule verdict-2.0, scoring score-2.0. How we score. Backtest.

Find them on

Maintained by

Maintained by 1 primary developer, 1 external contributor in the last 90 days.

  • strands-agents is a GitHub organization.
  • GitHub account created April 2025.
  • Top contributors by commits: abhisheksp 50%, zastrowm 50%.

Why now 4 Hacker News points in the last 7 days.

Stars StarsThe number of GitHub stars on the repository at our latest reading.
244
Gain 7d Gain 7dStars gained since our latest reading from at least 7 days ago.
n/a
Pace Velocity (Nx usual pace)This week's star gain divided by the project's usual weekly gain. The usual gain is the average weekly gain over the 4 weeks before (days 8 to 35 ago), counted as at least 10 stars. 2.0x means twice the usual pace. Without a reading from 35 days ago, the ranking assumes 2% of the stars the project had 7 days ago as its usual weekly gain. More on the methodology page
n/a
HN points HN pointsHacker News points added up across posts that mention the project, published in the last 7 days.
4 7 days
Downloads DownloadsDownloads per day of the project's package, as the registry (npm or PyPI) reports them.
n/a
Contributors Contributors, all timePeople and anonymous contributors who have ever committed to the repository, as GitHub counts them. A small number is context, not a flaw: many solid projects are kept by one or two people.
2
Last release Latest releaseDays since the latest GitHub release was published.
1 days ago

Gain 24h Gain 24hStars gained since our latest reading from at least 24 hours ago. n/a. Forks ForksThe number of GitHub forks of the repository at our latest reading. 10. Open issues Open issuesThe number of open issues on the repository at our latest reading, as GitHub counts them. 22. Days since push Days since pushDays since the last push to the repository. 0 days. Archived ArchivedWhether the owner has archived the repository on GitHub. An archived repository is read-only. no. Hacker News posts in 7 days Hacker News postsThe number of Hacker News posts that mention the project, published in the last 7 days.: 1. Watchers WatchersThe number of GitHub users watching the repository for notifications, at our latest reading. 0.

Facts

License
Apache-2.0 source, checked 9 Oct 2026
Language
Rust source, checked 9 Oct 2026
Homepage
https://strandsagents.com source, checked 9 Oct 2026
Last release
v0.1.0, 7 Oct 2026 source, checked 9 Oct 2026
Releases
1 source, checked 9 Oct 2026
Contributors
2 source, checked 9 Oct 2026
Archived
no source, checked 9 Oct 2026

Nerd stuff

Languages
Rust (detected), Shell (detected), Python (detected), JavaScript (detected)
Docs
docs/ folder (detected), examples/ folder (detected)
License
Apache-2.0 (detected)
Package ecosystem
Cargo (detected)

The Receipts

SourceEvidenceDate
Hacker NewsThread, 4 points, 0 comments8 Oct 2026

What changed recently

GitHub release dates we stored. We do not track license changes yet.

Cite this

box is a GitHub project at https://github.com/strands-agents/box written mainly in Rust, described there as "Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support planned".

Source: https://midorreal.com/project/strands-agents-box, checked 9 October 2026. The same facts as JSON: /project/strands-agents-box.json.

Rank history

Hot on Hacker News: #49 today.

New to our radar: #35 today.

Peak day: +17 stars on 9 Oct 2026, today.

Stars

8 Oct 20269 Oct 2026
Stars each day Stars each dayThe highest star count we recorded on each day., last 2 days. Without JavaScript this shows the last 30 days.

Events in this window

Dated items we stored, last 30 days. They sit near the chart, they do not explain it.

Stars gained each day Stars gained each dayThe difference in the daily peak star count between consecutive days that both have a reading., between readings on consecutive days. Last 30 days in the fallback.

Packages

? We have not checked the package registries for this project yet.

Signals

SourceWhat we measuredChecked
GitHub244 stars9 Oct 2026
Hacker News1 post stored, 4 points in the last 7 days9 Oct 2026
Feed mentionsNot tracked yet-
npmNot tracked yet-
PyPINot tracked yet-
Docker HubNot tracked yet-
crates.ioNot tracked yet-
HomebrewNot tracked yet-
deps.devNot tracked yet-
Hugging FaceNot tracked yet-
BlueskyNot tracked yet-
Stack ExchangeNot tracked yet-
YouTubeNot tracked yet-

Attention vs adoption

Attention: not enough data to rank
Star velocity against all tracked projects

Adoption: not enough data to rank
Downloads, dependents and pulls

Not enough comparable data yet to set attention against adoption. This describes the numbers; it is not a verdict.

Compared with MCP

MeasureThis projectCategory median
Star velocityno data0.7
Days since release1.50.9
Contributors, all time226
Median time to first reply on issuesno data21 hours
Commits in the last 30 days470

Contributors, all time: above 21% of MCP projects

Commits in the last 30 days: above 9% of MCP projects

Compared with the project's first category only. A percentile line appears only where at least 30 projects in the category have the measure. This describes the numbers; it is not a verdict.

Hacker News

Points by day Hacker News points by dayPoints on Hacker News posts that mention the project, grouped by the day each post was published. across 1 post and 1 day, 4 points in total.
PostPoints PointsThe points the post has on Hacker News.Comments CommentsThe number of comments on the post on Hacker News.Date
Hacker News post 4 0 8 Oct 2026

Repo health

  • Languages LanguagesShare of the repository's code by bytes, as GitHub's language detection reports it. The five biggest languages are named and the rest are grouped as Other.Rust 95%, Shell 4%, Python 1%
  • License LicenseThe SPDX license id GitHub detects, and a class: Open source (OSI) if the license is on the Open Source Initiative approved list, Source-available if the code is readable but the license limits use, Unclear if GitHub cannot match a known license, No license detected if it finds none. A public repository without a license is not open source.Apache-2.0, Open source (OSI)
  • Repository age Repository ageTime since the repository was created on GitHub. This is the repository, not necessarily the project, which may have existed elsewhere before.6 days, created 2 Oct 2026
  • Release dates Release datesThe date of the first and the latest GitHub release, and the latest release tag. Projects that ship without GitHub releases show none.First release 7 Oct 2026, current version v0.1.0 (7 Oct 2026)

Development

  • Commits in the last 7 days Commits in the last 7 daysCommits to the repository in the last 7 days, as GitHub counts them.4
  • Commits in the last 30 days Commits in the last 30 daysCommits to the repository in the last 30 days, as GitHub counts them.4
  • Commits in the last 90 days Commits in the last 90 daysCommits to the repository in the last 90 days, as GitHub counts them.4
  • Contributors, all time Contributors, all timePeople and anonymous contributors who have ever committed to the repository, as GitHub counts them. A small number is context, not a flaw: many solid projects are kept by one or two people.2, a small team
  • Releases ReleasesThe number of GitHub releases, and how many days ago the latest one was published.1, latest release 1 days ago
  • Releases in the last 90 days Releases in the last 90 daysHow many GitHub releases were published in the last 90 days.1
  • Issues in the last 30 days Issues in the last 30 daysIssues opened and issues closed in the last 30 days, as GitHub search counts them.19 opened, 2 closed
  • Pull requests merged in the last 30 days Pull requests merged in the last 30 daysPull requests merged in the last 30 days, as GitHub search counts them.3

Maintenance

  • Median time to close issues Median time to close issuesMedian time from opening to closing, over a sample of the last 30 closed issues.13 hours
  • Sampled issues with no reply Sampled issues with no replyHow many of the sampled closed issues never got a comment from someone other than their author.2 of 2
  • Stale open issues Stale open issuesOpen issues with no update in the last 90 days, as GitHub search counts them.0
  • Open pull requests Open pull requestsPull requests open now, as GitHub search counts them.5

Hygiene

  • Automated tests or builds (CI) Automated tests or builds (CI)Whether the repository has at least one GitHub Actions workflow file in .github/workflows.Yes
  • A tests folder A tests folderWhether the repository has a top-level folder named tests, test, __tests__ or spec.No
  • A license A licenseWhether GitHub detects a license file in the repository.Yes
  • Contributing guide Contributing guideWhether the repository has a contributing guide.Yes
  • Code of conduct Code of conductWhether GitHub finds a code of conduct in the repository.Yes
  • CODEOWNERS file CODEOWNERS fileWhether the repository has a CODEOWNERS file, which names who reviews changes to which files.No
  • A Dockerfile A DockerfileWhether the repository has a Dockerfile at its top level.No

Security

  • Security policy Security policyWhether the repository has a SECURITY.md or SECURITY.rst file.Yes
  • Unpatched high or critical advisories Unpatched high or critical advisoriesPublished GitHub security advisories rated high or critical on this repository that list a vulnerable version with no patched version.0
  • Signed latest release Signed latest releaseWhether the latest GitHub release has an attached signature file (.sig, .asc or .sigstore).No

Badge

For maintainers: one measured fact, no verdict. First spotted by Mid or Real at 153 stars on 8 Oct 2026

Markdown

[![Mid or Real](https://midorreal.com/badge/strands-agents-box.svg)](https://midorreal.com/project/strands-agents-box)

HTML

<a href="https://midorreal.com/project/strands-agents-box"><img src="https://midorreal.com/badge/strands-agents-box.svg" alt="Mid or Real"></a>

Verdict badge: Mid or Real: OVERHYPED It shows the verdict as this page shows it today.

Markdown

[![Mid or Real: OVERHYPED](https://midorreal.com/badge/strands-agents-box.svg?style=verdict)](https://midorreal.com/project/strands-agents-box)

HTML

<a href="https://midorreal.com/project/strands-agents-box"><img src="https://midorreal.com/badge/strands-agents-box.svg?style=verdict" alt="Mid or Real: OVERHYPED"></a>

Copy facts

Key facts as Markdown
# box

- Repository: https://github.com/strands-agents/box
- Page: https://midorreal.com/project/strands-agents-box
- Verdict: OVERHYPED (measured), scored 2026-10-09
- Scores: Hype 92, Reality 33, Hype Gap +59
- Stars: 244
- Methodology: https://midorreal.com/methodology#verdicts
- JSON: https://midorreal.com/project/strands-agents-box.json

Also as JSON.

First tracked 8 Oct 2026 at 153 stars.

Projects talked about on Hacker News

How we call a verdict

Is this your project? Claim it

Figures by method 1.0