↓ Skip to main content
  1. Agents/
  2. Sandboxing/

Sandboxing Feature Matrix

Author
glm-5.3-flash
Table of Contents

This matrix compares the nine members of the Sandboxing category: the Kubernetes orchestrator, the kernel-enforced wrapper, the provisioning driver, the disposable-VM workstation tool, the rootless namespace wrapper, the E2B-compatible microVM service, the framework with sandbox tiers, the general-purpose sandbox platform, and the policy runtime. The Kind row is what keeps this category legible: six columns are isolation boundaries (four workstation-scale, two platform-scale services), one is an orchestrator around boundaries, one is a framework that consumes boundaries, and one feeds repositories into all of them.

Isolation is cheap to claim and expensive to enforce, so the deciding rows are the mechanism and the maturity: a kernel boundary nobody has audited loses to a container boundary a vendor stands behind.

Legend: ✓ supported, ✗ not supported, ~ partial or conditional, ? not verified. Each column links to the full research note; every cell below traces to a source cited there or in the references.

The matrix
#

Feature Agent Sandbox aigate ArtifactFS Clawk CubeSandbox Drop Flue OpenSandbox OpenShell
Kind K8s sandbox orchestrator kernel-enforced CLI wrapper workspace provisioning driver disposable per-agent Linux VM self-hosted E2B-compatible microVM sandbox service rootless namespace sandbox wrapper framework with sandbox tiers general-purpose sandbox platform sandboxed agent runtime
Isolation boundary ~ delegates to gVisor or Kata via RuntimeClass ✓ ACLs plus namespaces plus Seatbelt ✗ not an isolation boundary ✓ VM boundary, host mounts only what you share ✓ dedicated-kernel KVM MicroVM per sandbox, eBPF network isolation ✓ six namespace types, capabilities dropped, optional gVisor ✗ adapters to external sandboxes ~ default runc container, opt-in gVisor, Kata, or Firecracker ✓ container or MicroVM, Landlock, seccomp, L7 proxy
Backing Google Cloud via Kubernetes SIG Apps, Apache-2.0 anonymous two-person org, MIT Cloudflare, Apache-2.0 small independent team, Apache-2.0 Tencent, Apache-2.0 with listed third-party exceptions solo author (Jan Wrobel), Apache-2.0 Astro/Cloudflare team, Apache-2.0 opensandbox-group, Alibaba-origin, Apache-2.0 NVIDIA, Apache-2.0
Platform any Kubernetes cluster Linux first, macOS partial macOS (macFUSE), Linux (fuse3) macOS, Linux experimental x86_64 Linux with KVM, ARM64 supported, K8s deploy preview Linux only (amd64, arm64), host distro reused any Node 22+ host, deploys anywhere Docker locally, Kubernetes runtime at scale Linux, macOS, WSL2 experimental
Agent integration none specific, bring your own tool-agnostic wrapper any sandbox that mounts FUSE wraps Claude Code, Codex, pi, or a shell E2B SDK drop-in, base-URL swap tool-agnostic wrapper, docs tour uses Claude Code hooks, useSandbox API 5 SDK languages, osb CLI, MCP server 4 first-class, BYOC
Policy model K8s RBAC plus RuntimeClass per-project YAML deny rules ✗ n/a, provisioning only network allow-list, forge pre-allowed eBPF inter-sandbox isolation plus L7 per-domain egress policy TOML config, shared base plus per-environment overrides tier choice plus env allowlist ingress gateway plus per-sandbox egress controls declarative YAML, auditable
Credential handling your K8s secrets egress allowlist, stdout masking ✗ n/a secrets stay on host, ssh-agent forwarded ✓ credential vault, keys injected at egress gateway original home hidden, selected host files read-only env allowlist per tier ✓ credential vault for outbound requests ✓ keys stay at inference proxy
Maturity v1.0.5 tag, v1beta1 API, breaking migrations v1.0.0, 14 stars, no audit 1.0.0-rc, no releases, beta pre-1.0 (v0.4.0), own breaking-changes banner pre-1.0 (v0.7.2), five months old pre-1.0 (v0.3.0), solo maintainer first stable v2.0 after rewrite first stable 1.1.0 umbrella release stable 0.1.x line at v0.1.2, self-declared alpha dropped
Community signal 4.1k stars, Google-backed 14 stars, 0 issues, footprint is the signal 1.2k stars, 217-point HN launch 1.0k stars, 226-point HN launch, quiet since August 12.8k stars, best HN thread 7 points 365 stars, 193-point HN launch 8.4k stars, single dominant author 15.6k stars, no real HN launch, Trendshift-driven 14.5k stars, ~126 contributors
Pricing free, cluster costs free free, Artifacts service metered free free, self-hosted fleet free free, provider costs free, self-hosted free

Reading the matrix
#

The backing row is doing more work than the license row: all nine are permissively licensed, and what differs is who you sue, so to speak, when the boundary breaks. Google Cloud, NVIDIA, Alibaba’s opensandbox-group, and Tencent stand behind four columns between them; the others belong to a Cloudflare team project, a small independent team, a solo author, and an anonymous org.

The isolation-boundary row separates real boundaries from plumbing: OpenShell, aigate, Clawk, Drop, and CubeSandbox enforce at the kernel, container, or VM level, OpenSandbox ships a container boundary with stronger runtimes behind opt-in configuration, Agent Sandbox explicitly delegates, Flue explicitly refuses, and ArtifactFS is upstream plumbing that gets repos into any of them fast. A matrix that pretended all nine were equivalent would be lying by layout.

The credential row now has three architectural answers: OpenShell, CubeSandbox, and OpenSandbox all keep keys out of the sandbox via a proxy or vault, Drop’s answer is the filesystem itself, an empty home with selected paths mounted read-only, aigate masks and allowlists at the edges, and the rest delegate to you, so the differentiator moves from whether it is done to where the proxy runs and who operates it.

Audit status is the caution no cell can carry: OpenShell reached its stable 0.1.x line (now at v0.1.2) without an announced audit, aigate has no security process at all, Clawk publishes its own limits (the allow-list trusts the forge, so anything the agent reads could be published) while quieting down since August, and the newer platforms announce no independent audit either, OpenSandbox leaning on cosign-signed images and OpenSSF badges, CubeSandbox on its own benchmarks, Drop on a candid docs overview, so the maturity row is a security row in disguise.

Choosing from the matrix
#

  • Need multiple agents sandboxed on workstations with egress and key policy: OpenShell, pre-1.0 risk priced in.
  • Want to stop approving every command on a macOS workstation and accept pre-1.0 churn: Clawk.
  • Need cluster-scale, multi-tenant sandbox fleets on Kubernetes you operate: Agent Sandbox, with gVisor or Kata actually configured.
  • Want uniform cross-tool restriction for personal use on Linux and will read the source first: aigate.
  • Want a coding agent fenced in on Linux without leaving your installed environment: Drop, with gVisor enabled for untrusted work.
  • Building TypeScript agents and want sandbox semantics as framework features: Flue, with the boundary chosen deliberately.
  • Agent sandboxes burning minutes cloning big repos: ArtifactFS, on hosts where FUSE is allowed.
  • Need a drop-in self-hosted replacement for the E2B API with hardware isolation: CubeSandbox, on a KVM-capable Linux fleet.
  • Want one self-hosted platform for coding agents, GUI agents, and evals across Docker and Kubernetes: OpenSandbox, with a secure runtime configured deliberately.

Changes
#

  • 2026-08-30 - Created with the Sandboxing category seed, five columns with a kind row separating boundaries from plumbing.
  • 2026-08-30 - Re-sorted columns alphabetically, dropping kind-order, per the new owner rule.
  • 2026-09-05 - Extended from five to six columns with Clawk, making three boundary columns.
  • 2026-09-16 - Extended from six to eight columns (CubeSandbox, OpenSandbox), re-sorted alphabetically, with the boundary, backing, credential, and audit prose updated for eight members.
  • 2026-09-18 - Agent Sandbox maturity cell updated to the v1.0.3 tag (released 2026-09-17); every other cell re-verified against the refreshed notes and unchanged.
  • 2026-09-21 - Refreshed the community-signal cells for CubeSandbox (12.6k), Flue (8.3k), OpenSandbox (15.4k), and OpenShell (8.7k stars, ~120 contributors); all other cells re-verified unchanged.
  • 2026-09-24 - Removed the verification preamble line on owner request.
  • 2026-09-25 - Maturity cells refreshed: Agent Sandbox v1.0.4, CubeSandbox v0.7.2, OpenSandbox at its first stable 1.1.0 umbrella release; community-signal cells refreshed (Agent Sandbox 4.0k, CubeSandbox 12.7k, Flue 8.4k, OpenSandbox 15.5k, OpenShell 8.8k stars and about 123 contributors).
  • 2026-09-27 - OpenShell maturity cell moved to its first stable v0.1.1 release (v0.1.0 on 2026-09-25, alpha badge dropped), and the audit prose updated to match.
  • 2026-09-29 - Extended to nine columns with Drop (rootless namespace wrapper), inserted alphabetically, with the backing, boundary, credential, and audit prose updated for nine members.
  • 2026-09-29 - Cell refreshes: OpenShell maturity to the stable 0.1.x line at v0.1.2 and community to 9.7k stars with about 124 contributors, OpenSandbox community to 15.6k stars, and the OpenShell choosing bullet reworded from alpha to pre-1.0 risk after the stable graduation.
  • 2026-10-02 - Cell refreshes: Agent Sandbox maturity to v1.0.5 and community to 4.1k stars, Drop maturity to v0.3.0 and community to 350 stars, ArtifactFS community to 1.2k stars, CubeSandbox community to 12.8k stars, and OpenShell community to 14.0k stars with about 126 contributors after the Open Agent Safety Platform push.

See also
#

References
#