Agent security and policy

strands-agents/

box

Sandbox engine for AI agents: OS isolation + Dogwood policies control files, network, and tool calls, with secrets injected outside the agent.

What’s new here

Box combines OS-level sandboxing with a Dogwood policy engine whose enforcement points (Strands Shell, Monty for Python, egress gateway, MCP broker) share a single event history. A rule can reference earlier actions and elapsed time, so a file read through one interpreter can cause the gateway to deny a later outbound HTTP request. The credential injection feature lets the gateway sign permitted requests with API keys or AWS SigV4, so the agent process never sees the underlying secret.

What it does

Box wraps an agent binary in an OS sandbox that enforces direct filesystem and network grants from box.toml. Operations that go through Box’s own interpreters (Strands Shell, Monty for Python) or gateways (egress proxy, MCP broker) are also evaluated against Dogwood rules in policy.dw before they execute.

Dogwood uses permit and forbid rules. Everything the engine checks is denied by default; a matching permit must exist. A forbid overrides any permit. Rules can reference earlier events and elapsed time, so policy decisions can depend on the agent’s recent history, not just the current request.

Box records every policy decision as OTLP JSON in <box_dir>/private/telemetry/records.jsonl. External programs and local MCP servers launched by the agent run in their own sandboxes with separately configured file grants, and their network traffic routes through the egress gateway by default.

Who it’s for

Teams running coding or tool-use agents who want to write policy rules that span shell, Python, HTTP, and MCP tool calls in one place, or who need to supply API credentials to an agent without passing them into the agent process. Box is harness-agnostic: you choose the agent program or binary to run. Current support is macOS on Apple silicon (macOS 15 or later); Linux support is listed as planned.

Try it

Download and verify the binaries with the provided script:

curl -fsSL https://raw.githubusercontent.com/strands-agents/box/main/download.sh | sh
./box-core/box --version

Or build from source with Cargo:

git clone https://github.com/strands-agents/box.git
cd box
cargo build --release -p strands-box -p strands-box-containment

The getting-started guide requires a Mac with Apple silicon, macOS 15 or later, Node.js 22.21 or later from Homebrew, and access to Claude Opus 5 on Amazon Bedrock in us-west-2. After setup, write box.toml and policy.dw, then run the box as described in docs/user/getting-started.md.

How mature is it

Created 2026-10-02, with one release (v0.1.0, tagged 2026-10-07). The README labels this a preview. 308 stars, 14 forks, 3 contributors, 6 commits in the last 90 days, 32 open issues and 48 open pull requests. Licensed Apache-2.0. Linux support is listed as planned but not yet available.