Nixcage – Sandbox AI coding agents per project with Nix and direnv
direnv auto-activation with bubblewrap sandboxing isolates agents per project.
Lightweight and declarative sandboxing for AI agents on Linux and macOS using Nix.
Sandbox Claude Code and Aider before they read your SSH keys.
Developers using CLI-based AI coding agents
Firecracker · gVisor · Docker
direnv auto-activation with bubblewrap sandboxing isolates agents per project.
Kernel-enforced agent sandboxing that blocks .env access without container overhead.
macOS Endpoint Security frameworks beat sandbox-exec for AI agent isolation.
macOS sandbox-exec guards AI agents so rm -rf can't wreck your whole machine.
TLA+ verified sandbox makes --dangerously-skip-permissions safe for Claude Code and other agents on macOS.
Full macOS isolation beats containers for agents needing GUI apps and native tools.