#55th of 8 in Sandboxes

microsandbox

Local microVMs for untrusted code with fork, snapshot and SDKs

Stars
8.6k
License
Apache-2.0
Last commit
Oct 2026
Last release
Oct 2026

Overview

Boots OCI images as hardware-isolated microVMs in under 100 ms on Linux with KVM, Apple Silicon macOS or Windows with WHP, driven by the msb CLI or embedded via TypeScript, Rust, Python, Go and Ruby SDKs with no daemon. Running sandboxes fork live or snapshot and restore; network access is allow-listed per host and secrets are injected only toward an allowed host. For agent-generated code, CI jobs and plugins.

Who it is for: Teams running agent-generated code and untrusted jobs locally

Strengths

  • Sub-100 ms average boot; sandboxes spawn as child processes of your app
  • Live fork and full snapshot restore with copy-on-write memory
  • Per-sandbox network allow-lists and secrets scoped to one host
  • MCP server and agent skills let coding agents create their own sandboxes

Weaknesses

  • Beta software; breaking changes and missing features expected
  • Needs KVM on Linux, Apple Silicon on macOS or WHP on Windows; no Intel Mac
  • No Dockerfile or compose file; it replaces containers rather than running in one
  • Image pulls on first create add startup time

What it needs

  • no GPU
  • Docker
  • Needs KVM (Linux), Apple Silicon (macOS) or WHP (Windows)

Also in Sandboxes

See all 8
Also in Sandboxes
RankProjectScore
1LightpandaHeadless browser written in Zig for AI agents and scraping36.2k stars, AGPL-3.078 out of 100
2ObscuraRust headless browser with CDP, native rendering and stealth mode28.7k stars, Apache-2.071 out of 100
3NemoClawNVIDIA reference stack running OpenClaw and Hermes inside OpenShell sandboxes22.7k stars, Apache-2.071 out of 100
#4OpenShellPolicy-enforced sandbox runtime for autonomous agents with credential brokering15.7k stars, Apache-2.069 out of 100
#6Steel BrowserBrowser API that manages Chrome sessions for Puppeteer, Playwright and Selenium7.8k stars, Apache-2.060 out of 100