Skip to content
Sandboxing

Five minutes

Sandbox your agent in five minutes

Three dials matter: network, credentials and isolation. These steps give you a working sandbox today. You can tighten the policy later.
  1. 1

    Install it

    terminal
    $ brew install docker/sbx/sbx
    $ sbx login

    You need an Apple silicon Mac. Logging in opens a browser window.

  2. 2

    Pull the agent image first

    terminal
    $ sbx run claude
    # the first run takes a minute or two, so do this before you need it
  3. 3

    Run your agent inside the box

    terminal
    $ sbx run claude
    # same prompts and same workflow, but now the box is in charge
  4. 4

    Check what is blocked

    terminal
    $ sbx policy check network <host>
    $ sbx policy log
  5. 5

    Start over when it breaks

    terminal
    $ sbx rm <sandbox>
    $ sbx run claude # a fresh one in seconds
  6. 6

    A lighter option: srt

    terminal
    $ srt "cat ~/.ssh/id_demo"
    # Operation not permitted
    $ srt "curl example.com"
    # blocked

    Reads are open by default. Add denyRead to lock those down too.

If you do one thing, lock the exits. Limiting files stops an agent wrecking your machine, controlling outbound traffic stops it robbing you, and isolation stops it escaping.

These commands follow Docker's docs, and flags change between versions. If one doesn't work, check the built in help for the version you have installed.