OpenClaw plugin – hard budget limits for agent tool calls
Reserve-before-execute budget protocol prevents agents from burning money unexpectedly.
WASM sandbox for untrusted plugins with syscall budgets
Deterministic budget enforcement on WASM syscalls—clean threat model, but early-stage tooling.
Platform teams running plugin systems or multi-tenant workloads with untrusted code
WasmEdge · Wasmtime (upstream) · gVisor (for containers)
Reserve-before-execute budget protocol prevents agents from burning money unexpectedly.
Virtualenv for system isolation—your configs carry over but SSH keys stay protected.
gVisor sandboxing with filesystem snapshots for warm AI code execution environments.
Domain-allowlist network sandbox for any process—no VM, native Landlock and overlayfs.
Tracks tokens not dollars—clever design that avoids pricing drift headaches.
Macaroon-based budget enforcement for AI agents—fills a real economic governance gap.