Sandboxes

Isolated runtimes where agents execute code, browse or use tools safely.

Lightpanda leads with 78, ahead of Obscura (71) and NemoClaw (71). 8 projects ranked by score.

The ranking

Sandboxes: full ranking
RankProjectAdoptionFreshnessMaintenanceEasy to runAgent-readyScore
1LightpandaHeadless browser written in Zig for AI agents and scraping36.3k stars, AGPL-3.0, last commit Oct 20268510092507078 out of 100
2ObscuraRust headless browser with CDP, native rendering and stealth mode28.8k stars, Apache-2.0, last commit Oct 20267210091503071 out of 100
3NemoClawNVIDIA reference stack running OpenClaw and Hermes inside OpenShell sandboxes22.7k stars, Apache-2.0, last commit Oct 20266210076508571 out of 100
#4OpenShellPolicy-enforced sandbox runtime for autonomous agents with credential brokering15.8k stars, Apache-2.0, last commit Oct 20264410088508569 out of 100
#5microsandboxLocal microVMs for untrusted code with fork, snapshot and SDKs8.6k stars, Apache-2.0, last commit Oct 20263010087503061 out of 100
#6Steel BrowserBrowser API that manages Chrome sessions for Puppeteer, Playwright and Selenium7.8k stars, Apache-2.0, last commit Oct 2026221004283060 out of 100
#7Browser Use Web UIGradio UI for running browser-use agents with your own Chrome16.6k stars, MIT, last commit May 20265266067048 out of 100
#8Open TerminalREST-driven shell and file sandbox for AI agents, from Open WebUI3.3k stars, MIT, last commit Oct 202651007233046 out of 100

Momentum, Verified build, Docs and Privacy are not measured yet; their weight goes to the signals shown. A dash means the signal is not scored for that kind of project. Hover a number for its rating in words.

Reviews

178 out of 100

Lightpanda

Headless browser written in Zig for AI agents and scraping

36.3k stars, AGPL-3.0, last commit Oct 2026

Lightpanda is a headless browser written in Zig, built on V8 for JavaScript, libcurl for HTTP and html5ever for parsing, with no graphical rendering. It exposes a CDP server on port 9222 for Puppeteer and Playwright, plus WebDriver BiDi, an MCP server, and a built-in LLM agent mode. It can also dump pages as HTML, Markdown, PNG or PDF from the command line.

Strengths

  • README benchmark: 123MB peak vs 2GB for headless Chrome over 100 pages
  • CDP server works with Puppeteer; WebDriver BiDi also supported
  • MCP server over stdio or HTTP, with isolated or shared sessions
  • Agent output saved as replayable JavaScript scripts that need no LLM at runtime

Weaknesses

  • No native Windows build; WSL2 required
  • Linux binaries need glibc; they fail on Alpine/musl
  • Telemetry is on by default; opt out via environment variable
  • Not a full browser: no graphical rendering, partial Web Platform Tests coverage
  • no GPU
  • Docker
  • Models: Anthropic, OpenAI, Gemini, Vertex AI, Mistral
  • port 9222
271 out of 100

Obscura

Rust headless browser with CDP, native rendering and stealth mode

28.8k stars, Apache-2.0, last commit Oct 2026

Headless browser engine in Rust running V8 that speaks the Chrome DevTools Protocol, so Puppeteer and Playwright connect on port 9222 as if to Chrome. Ships its own layout and paint engine for screenshots, screencasts and PDF export, a stealth build with per-session fingerprint randomization, a parallel scrape command and an MCP server. Claims 30 MB memory and 85 ms page loads against 200+ MB and about 500 ms for Chrome.

Strengths

  • Single binary around 70 MiB, no Chrome or Node.js; distroless Docker image about 57 MB
  • Stealth build randomizes fingerprints per session and blocks 3,520 tracker domains
  • SSRF protection blocks private IPs by default; CDP token on the Docker image
  • Fetch.takeResponseBodyAsStream and IO.read stream large downloads in chunks

Weaknesses

  • Independent rendering engine; long-tail CSS, media playback and fonts can differ from Chromium
  • Stealth builds need CMake, Clang and libclang; first source build takes about 5 minutes
  • README carries heavy proxy-vendor sponsorship and discount codes
  • Linux binaries target glibc 2.35 or newer (Ubuntu 22.04)
  • no GPU
  • Docker
  • port 9222
371 out of 100

NemoClaw

NVIDIA reference stack running OpenClaw and Hermes inside OpenShell sandboxes

22.7k stars, Apache-2.0, last commit Oct 2026

CLI and installer that provision OpenShell sandboxes for OpenClaw (default), Hermes or LangChain Deep Agents Code, with guided onboarding, inference provider selection, baseline network policies with operator approval, managed integrations and persistent sandbox state. Express install targets DGX hosts and Windows WSL; a starter prompt lets Cursor, Claude Code or Codex drive setup. For personal agents with kernel-enforced isolation.

Strengths

  • Three supported agents: OpenClaw, Hermes, LangChain Deep Agents Code
  • Network policy with operator approval flow and egress control from OpenShell
  • Express preset install on DGX and WSL hosts
  • Documented sandbox hardening: capability drops and process limits

Weaknesses

  • Alpha project; maintainers review issues without guaranteed response times
  • Depends on OpenShell as the runtime; details live in NVIDIA docs, not the README
  • README is mostly links; no architecture or resource figures in the repo itself
  • Supported platforms are limited to those on the prerequisites page
  • no GPU
  • Docker
  • Needs NVIDIA OpenShell, Inference provider (local or routed)
  • Models: providers configured through OpenShell routed inference
#469 out of 100

OpenShell

Policy-enforced sandbox runtime for autonomous agents with credential brokering

15.8k stars, Apache-2.0, last commit Oct 2026

Runs each agent in a sandbox with kernel-enforced limits on file access and system calls; every outbound connection passes a policy check, and agents never see real credentials, which a gateway injects only for approved endpoints. Policy changes are checked with formal verification before approval. Installs via a shell script on Linux, Apple Silicon macOS or WSL 2; Helm for Kubernetes; SDKs for Python, TypeScript, Go and Rust.

Strengths

  • Credentials attached by the gateway only to approved endpoints; sandboxes never hold them
  • Formal verification flags risky new access before a policy change is applied
  • Kubernetes deployment via Helm; GPU use inside sandboxes documented
  • Python, TypeScript, Go and Rust SDKs plus agent skills via npx skills add

Weaknesses

  • Windows support is WSL 2 only and experimental
  • Default sandbox image is minimal Ubuntu with no agent; running one follows the docs walkthrough
  • Anonymous telemetry on by default; disable with OPENSHELL_TELEMETRY_ENABLED=false
  • Kubernetes installs require a CNI that enforces NetworkPolicy
  • no GPU
  • Docker + Compose
  • Needs Docker, Podman or host virtualization
  • Models: any provider via routed inference credentials
#561 out of 100

microsandbox

Local microVMs for untrusted code with fork, snapshot and SDKs

8.6k stars, Apache-2.0, last commit Oct 2026

Boots OCI images as hardware-isolated microVMs in under 100 ms on Linux with KVM, Apple Silicon macOS or Windows with WHP, driven by the msb CLI or embedded via TypeScript, Rust, Python, Go and Ruby SDKs with no daemon. Running sandboxes fork live or snapshot and restore; network access is allow-listed per host and secrets are injected only toward an allowed host. For agent-generated code, CI jobs and plugins.

Strengths

  • Sub-100 ms average boot; sandboxes spawn as child processes of your app
  • Live fork and full snapshot restore with copy-on-write memory
  • Per-sandbox network allow-lists and secrets scoped to one host
  • MCP server and agent skills let coding agents create their own sandboxes

Weaknesses

  • Beta software; breaking changes and missing features expected
  • Needs KVM on Linux, Apple Silicon on macOS or WHP on Windows; no Intel Mac
  • No Dockerfile or compose file; it replaces containers rather than running in one
  • Image pulls on first create add startup time
  • no GPU
  • Docker
  • Needs KVM (Linux), Apple Silicon (macOS) or WHP (Windows)
#660 out of 100

Steel Browser

Browser API that manages Chrome sessions for Puppeteer, Playwright and Selenium

7.8k stars, Apache-2.0, last commit Oct 2026

REST API and UI on port 3000 that launches Chrome sessions with persisted cookies and storage, proxy chains, stealth plugins and request logging, then hands you a CDP endpoint for Puppeteer or Playwright or a WebDriver endpoint for Selenium. Quick-action endpoints return a page as HTML, markdown, screenshot or PDF. Runs from a prebuilt ghcr.io image or docker compose; Node and Python SDKs target cloud or self-hosted instances.

Strengths

  • One image serves API, UI and console debugger (ports 3000 and 9223)
  • Session API persists cookies and storage; Selenium sessions via isSelenium
  • Swagger UI at /documentation on the local instance
  • Node and Python SDKs switch between cloud and self-host with baseURL

Weaknesses

  • Public beta; API still changing
  • Runs full Chrome; needs a Chrome executable when run outside Docker
  • Selenium integration lacks some features of the CDP session API
  • Apple Silicon compose needs DOCKER_DEFAULT_PLATFORM=linux/arm64
  • no GPU
  • Docker + Compose
  • Needs Google Chrome (non-Docker runs), Node.js (non-Docker runs)
  • port 3000
#748 out of 100

Browser Use Web UI

Gradio UI for running browser-use agents with your own Chrome

16.6k stars, MIT, last commit May 2026

Gradio front end over the browser-use library that takes a task, drives a Playwright browser with an LLM (Google, OpenAI, Azure OpenAI, Anthropic, DeepSeek or Ollama) and shows the run. Can attach to your own Chrome profile to reuse logins, keep the browser open between tasks and record video. Runs with uv and Python 3.11 on port 7788, or via docker compose with a noVNC viewer on port 6080.

Strengths

  • Own-browser mode reuses existing Chrome logins and cookies
  • Docker compose includes noVNC so you can watch the agent at localhost:6080
  • Persistent browser sessions keep history visible between tasks
  • Supports Ollama and DeepSeek-R1 alongside cloud providers

Weaknesses

  • Changelog stops in January 2025; last commit May 2026
  • Default VNC password is published in the README; change VNC_PASSWORD
  • Own-browser mode requires closing all Chrome windows and using another browser for the UI
  • Gradio single-user UI; no auth or multi-user features described
  • no GPU
  • Docker + Compose
  • Needs Playwright browsers, LLM API key or Ollama, Chrome (optional, own-browser mode)
  • Models: Google, OpenAI, Azure OpenAI, Anthropic, DeepSeek
  • port 7788
#846 out of 100

Open Terminal

REST-driven shell and file sandbox for AI agents, from Open WebUI

3.3k stars, MIT, last commit Oct 2026

Container or pip package exposing a shell and file management over a REST API with an API key on port 8000, so agents can run commands and code. The latest image (about 4 GB) bundles Python, Node.js, gcc, ffmpeg, LibreOffice, LaTeX and the Docker CLI behind an egress firewall; slim (430 MB) and alpine (230 MB) variants keep git, curl and jq. Integrates with Open WebUI as a terminal with a file sidebar.

Strengths

  • API key auto-generated if unset; interactive API docs at /docs
  • Extra apt, pip and npm packages installed at startup via env vars
  • Four image variants from 230 MB alpine to a 4 GB full toolkit
  • Office previews: DOCX and PPTX rendered to PDF when LibreOffice is present

Weaknesses

  • Multi-user mode shares one container and is explicitly not a security boundary
  • Per-user isolation requires Terminals, which needs an Open WebUI Enterprise license
  • Mounting the Docker socket gives the container root-equivalent host access
  • Bare-metal mode runs commands directly as your user with no sandbox
  • no GPU
  • Docker
  • port 8000

Written from each project's README and checked facts. Spot something wrong? Report it on GitHub (opens in a new tab).