{"name":"box","repo":"strands-agents/box","url":"https://midorreal.com/project/strands-agents-box","repository":"https://github.com/strands-agents/box","description":"Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support planned.","facts":{"license":{"value":"Apache-2.0","source":"https://github.com/strands-agents/box","checked":"9 Oct 2026"},"language":{"value":"Rust","source":"https://github.com/strands-agents/box","checked":"9 Oct 2026"},"homepage":{"value":"https://strandsagents.com","source":"https://strandsagents.com","checked":"9 Oct 2026"},"last_release":{"value":"v0.1.0, 7 Oct 2026","source":"https://github.com/strands-agents/box/releases","checked":"9 Oct 2026"},"releases":{"value":"1","source":"https://github.com/strands-agents/box/releases","checked":"9 Oct 2026"},"contributors":{"value":"2","source":"https://github.com/strands-agents/box/graphs/contributors","checked":"9 Oct 2026"},"archived":{"value":"no","source":"https://github.com/strands-agents/box","checked":"9 Oct 2026"}},"stars":244.0,"writeup":{"what_it_is":"Strands Box is an open-source sandbox engine for running AI agents with restricted access to files, programs, and network. It combines OS-level isolation with Dogwood policy rules that control what agents can execute, read, write, and reach.","audience":"Developers deploying AI agents who need security controls.","claims":[{"kind":"specific","claim":"Supports macOS on Apple silicon with Linux support planned","excerpt":"Box currently supports local execution on macOS with Apple silicon.","status":"not_checked"},{"kind":"specific","claim":"Uses Dogwood policies with default-deny enforcement","excerpt":"Operations checked by the engine are denied by default: a matching `permit` must allow the operation, and a matching `forbid` overrides that permission.","status":"not_checked"},{"kind":"specific","claim":"Supports credential injection that keeps secrets outside the agent","excerpt":"The gateway authenticates permitted requests with configured API credentials or AWS SigV4 signing. The agent does not receive the underlying secrets.","status":"not_checked"},{"kind":"specific","claim":"Records policy decisions in OTLP JSON format","excerpt":"Box records policy decisions in OTLP JSON. By default, records go to `<box_dir>/private/telemetry/records.jsonl`.","status":"not_checked"}],"alternatives":[],"written_by":"AI, from the project's README","date":"2026-10-09"},"why_now":null,"owner_supplied":null,"score":{"verdict":"overhyped","hype":92,"reality":33,"gap":59,"momentum":null,"confidence":60,"version":"score-2.0","rule":"verdict-2.0","calculated_at":"2026-10-09T05:00:00+00:00","verdict_source":"rule"},"early_read":null,"changes":[{"date":"2026-10-07T17:24:27+00:00","text":"Latest release v0.1.0","source":"https://github.com/strands-agents/box/releases"},{"date":"2026-10-02T20:34:08+00:00","text":"Repository created","source":"https://github.com/strands-agents/box"}],"cite":"box is a GitHub project at https://github.com/strands-agents/box written mainly in Rust, described there as \"Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support planned\".","attribution":"Data from Mid or Real, https://midorreal.com/project/strands-agents-box, checked 9 October 2026. Attribution with a link is required."}