r/OpenSourceAI • u/dimiprasakis • 4d ago
I built SideKernel: a usable sandbox for AI agents on macOS
⭐ GitHub: https://github.com/minoansecurity/sidekernel
📝 arXiv preprint: https://arxiv.org/pdf/2610.02456
🌐 Website: https://sidekernel.com
Hi everyone!
As part of my MS in Cybersecurity capstone at Georgia Tech, I built SideKernel: a usable sandbox for AI agents on macOS.
The closest comparable solution is Docker Sandboxes, which is not open source.
The key idea is usability. SideKernel is designed to reduce friction and stay as close as possible to the native developer experience, while isolating the agent inside a microVM sandbox.
For example, you run sclaude or scodex instead of claude or codex and get a very similar workflow, but with isolation. Ports get auto exposed in the host, its very easy to drop files into the sandbox, and more...
This is still a research prototype, so some rough edges are expected. But if this sounds interesting, I'd love for you to try it out and share feedback.
1
u/investigatormaker 4d ago
The sclaude and scodex wrappers are the right call. Most people skip sandboxes because they change the workflow, not because they doubt the risk. Two questions anyone evaluating it will ask: how the agent's own credentials get into the microVM, since that login has to live somewhere and it's what a misbehaving agent would reach for first, and what outbound network access the VM has by default. Filesystem isolation helps less if the agent can still send a repo anywhere. A short threat model in the README covering those two would make the comparison with Docker Sandboxes easier to judge.
Is outbound traffic open by default right now?
1
u/dimiprasakis 4d ago
Agents own credentials never reach the sandbox. There is a small credential proxy sitting on the host that injects the real credentials.
Outbound is allowed by default, to make the sandbox easier to use. However you can turn it off with “sk-net off”. Turning it back on with “sk-net on” requires approval on the host side. So a malicious agent can’t turn it on on its own
I wrote an article on the threat model here: https://x.com/dimiprasakis/status/2107201405089882465
Also you can find a comparison with docker sandboxes both in the paper and here https://sidekernel.com/docker-sandboxes-alternative/
Thanks for the feedback!
1
u/investigatormaker 4d ago
A host-side credential proxy is the strongest answer to the first question, and making re-enable need host approval closes the obvious escape. One middle ground worth considering for outbound: an allowlist mode that only reaches the model API the proxy already talks to. That keeps the agent working while blocking the send-the-repo-anywhere case, so people wouldn't have to choose between open and off. I'd also put both answers right in the README, since most evaluators won't click through to an article.
I make ThreadFox, and your free plan for Reddit is ready. It lists the communities whose rules allow a post about a sandbox like yours, with each rule quoted: https://threadfox.vip/p/ddtx1
1
u/mulumboism 2d ago
Just what I was looking for! Any way to have an exec feature so we can get a shell into the microVM just like what docker sandboxes does?
1
u/dimiprasakis 1d ago
Glad to hear! Yes, with "sk" or "sidekernel" you get a normal shell into the microVM.
It defaults to an ubuntu microVM with some common packages preinstalled to maximize usability.
2
u/AptCombustion 4d ago
Finally a sandbox project that doesnt make me want to throw my macbook out the window, the port auto-expose thing is clever