This matrix compares the nine members of the Sandboxing category: the Kubernetes orchestrator, the kernel-enforced wrapper, the provisioning driver, the disposable-VM workstation tool, the rootless namespace wrapper, the E2B-compatible microVM service, the framework with sandbox tiers, the general-purpose sandbox platform, and the policy runtime. The Kind row is what keeps this category legible: six columns are isolation boundaries (four workstation-scale, two platform-scale services), one is an orchestrator around boundaries, one is a framework that consumes boundaries, and one feeds repositories into all of them.
Isolation is cheap to claim and expensive to enforce, so the deciding rows are the mechanism and the maturity: a kernel boundary nobody has audited loses to a container boundary a vendor stands behind.
Legend: ✓ supported, ✗ not supported, ~ partial or conditional, ? not verified. Each column links to the full research note; every cell below traces to a source cited there or in the references.
The matrix #
| Feature | Agent Sandbox | aigate | ArtifactFS | Clawk | CubeSandbox | Drop | Flue | OpenSandbox | OpenShell |
|---|---|---|---|---|---|---|---|---|---|
| Kind | K8s sandbox orchestrator | kernel-enforced CLI wrapper | workspace provisioning driver | disposable per-agent Linux VM | self-hosted E2B-compatible microVM sandbox service | rootless namespace sandbox wrapper | framework with sandbox tiers | general-purpose sandbox platform | sandboxed agent runtime |
| Isolation boundary | ~ delegates to gVisor or Kata via RuntimeClass | ✓ ACLs plus namespaces plus Seatbelt | ✗ not an isolation boundary | ✓ VM boundary, host mounts only what you share | ✓ dedicated-kernel KVM MicroVM per sandbox, eBPF network isolation | ✓ six namespace types, capabilities dropped, optional gVisor | ✗ adapters to external sandboxes | ~ default runc container, opt-in gVisor, Kata, or Firecracker | ✓ container or MicroVM, Landlock, seccomp, L7 proxy |
| Backing | Google Cloud via Kubernetes SIG Apps, Apache-2.0 | anonymous two-person org, MIT | Cloudflare, Apache-2.0 | small independent team, Apache-2.0 | Tencent, Apache-2.0 with listed third-party exceptions | solo author (Jan Wrobel), Apache-2.0 | Astro/Cloudflare team, Apache-2.0 | opensandbox-group, Alibaba-origin, Apache-2.0 | NVIDIA, Apache-2.0 |
| Platform | any Kubernetes cluster | Linux first, macOS partial | macOS (macFUSE), Linux (fuse3) | macOS, Linux experimental | x86_64 Linux with KVM, ARM64 supported, K8s deploy preview | Linux only (amd64, arm64), host distro reused | any Node 22+ host, deploys anywhere | Docker locally, Kubernetes runtime at scale | Linux, macOS, WSL2 experimental |
| Agent integration | none specific, bring your own | tool-agnostic wrapper | any sandbox that mounts FUSE | wraps Claude Code, Codex, pi, or a shell | E2B SDK drop-in, base-URL swap | tool-agnostic wrapper, docs tour uses Claude Code | hooks, useSandbox API | 5 SDK languages, osb CLI, MCP server | 4 first-class, BYOC |
| Policy model | K8s RBAC plus RuntimeClass | per-project YAML deny rules | ✗ n/a, provisioning only | network allow-list, forge pre-allowed | eBPF inter-sandbox isolation plus L7 per-domain egress policy | TOML config, shared base plus per-environment overrides | tier choice plus env allowlist | ingress gateway plus per-sandbox egress controls | declarative YAML, auditable |
| Credential handling | your K8s secrets | egress allowlist, stdout masking | ✗ n/a | secrets stay on host, ssh-agent forwarded | ✓ credential vault, keys injected at egress gateway | original home hidden, selected host files read-only | env allowlist per tier | ✓ credential vault for outbound requests | ✓ keys stay at inference proxy |
| Maturity | v1.0.5 tag, v1beta1 API, breaking migrations | v1.0.0, 14 stars, no audit | 1.0.0-rc, no releases, beta | pre-1.0 (v0.4.0), own breaking-changes banner | pre-1.0 (v0.7.2), five months old | pre-1.0 (v0.3.0), solo maintainer | first stable v2.0 after rewrite | first stable 1.1.0 umbrella release | stable 0.1.x line at v0.1.2, self-declared alpha dropped |
| Community signal | 4.1k stars, Google-backed | 14 stars, 0 issues, footprint is the signal | 1.2k stars, 217-point HN launch | 1.0k stars, 226-point HN launch, quiet since August | 12.8k stars, best HN thread 7 points | 365 stars, 193-point HN launch | 8.4k stars, single dominant author | 15.6k stars, no real HN launch, Trendshift-driven | 14.5k stars, ~126 contributors |
| Pricing | free, cluster costs | free | free, Artifacts service metered | free | free, self-hosted fleet | free | free, provider costs | free, self-hosted | free |
Reading the matrix #
The backing row is doing more work than the license row: all nine are permissively licensed, and what differs is who you sue, so to speak, when the boundary breaks. Google Cloud, NVIDIA, Alibaba’s opensandbox-group, and Tencent stand behind four columns between them; the others belong to a Cloudflare team project, a small independent team, a solo author, and an anonymous org.
The isolation-boundary row separates real boundaries from plumbing: OpenShell, aigate, Clawk, Drop, and CubeSandbox enforce at the kernel, container, or VM level, OpenSandbox ships a container boundary with stronger runtimes behind opt-in configuration, Agent Sandbox explicitly delegates, Flue explicitly refuses, and ArtifactFS is upstream plumbing that gets repos into any of them fast. A matrix that pretended all nine were equivalent would be lying by layout.
The credential row now has three architectural answers: OpenShell, CubeSandbox, and OpenSandbox all keep keys out of the sandbox via a proxy or vault, Drop’s answer is the filesystem itself, an empty home with selected paths mounted read-only, aigate masks and allowlists at the edges, and the rest delegate to you, so the differentiator moves from whether it is done to where the proxy runs and who operates it.
Audit status is the caution no cell can carry: OpenShell reached its stable 0.1.x line (now at v0.1.2) without an announced audit, aigate has no security process at all, Clawk publishes its own limits (the allow-list trusts the forge, so anything the agent reads could be published) while quieting down since August, and the newer platforms announce no independent audit either, OpenSandbox leaning on cosign-signed images and OpenSSF badges, CubeSandbox on its own benchmarks, Drop on a candid docs overview, so the maturity row is a security row in disguise.
Choosing from the matrix #
- Need multiple agents sandboxed on workstations with egress and key policy: OpenShell, pre-1.0 risk priced in.
- Want to stop approving every command on a macOS workstation and accept pre-1.0 churn: Clawk.
- Need cluster-scale, multi-tenant sandbox fleets on Kubernetes you operate: Agent Sandbox, with gVisor or Kata actually configured.
- Want uniform cross-tool restriction for personal use on Linux and will read the source first: aigate.
- Want a coding agent fenced in on Linux without leaving your installed environment: Drop, with gVisor enabled for untrusted work.
- Building TypeScript agents and want sandbox semantics as framework features: Flue, with the boundary chosen deliberately.
- Agent sandboxes burning minutes cloning big repos: ArtifactFS, on hosts where FUSE is allowed.
- Need a drop-in self-hosted replacement for the E2B API with hardware isolation: CubeSandbox, on a KVM-capable Linux fleet.
- Want one self-hosted platform for coding agents, GUI agents, and evals across Docker and Kubernetes: OpenSandbox, with a secure runtime configured deliberately.
Changes #
- 2026-08-30 - Created with the Sandboxing category seed, five columns with a kind row separating boundaries from plumbing.
- 2026-08-30 - Re-sorted columns alphabetically, dropping kind-order, per the new owner rule.
- 2026-09-05 - Extended from five to six columns with Clawk, making three boundary columns.
- 2026-09-16 - Extended from six to eight columns (CubeSandbox, OpenSandbox), re-sorted alphabetically, with the boundary, backing, credential, and audit prose updated for eight members.
- 2026-09-18 - Agent Sandbox maturity cell updated to the v1.0.3 tag (released 2026-09-17); every other cell re-verified against the refreshed notes and unchanged.
- 2026-09-21 - Refreshed the community-signal cells for CubeSandbox (12.6k), Flue (8.3k), OpenSandbox (15.4k), and OpenShell (8.7k stars, ~120 contributors); all other cells re-verified unchanged.
- 2026-09-24 - Removed the verification preamble line on owner request.
- 2026-09-25 - Maturity cells refreshed: Agent Sandbox v1.0.4, CubeSandbox v0.7.2, OpenSandbox at its first stable 1.1.0 umbrella release; community-signal cells refreshed (Agent Sandbox 4.0k, CubeSandbox 12.7k, Flue 8.4k, OpenSandbox 15.5k, OpenShell 8.8k stars and about 123 contributors).
- 2026-09-27 - OpenShell maturity cell moved to its first stable v0.1.1 release (v0.1.0 on 2026-09-25, alpha badge dropped), and the audit prose updated to match.
- 2026-09-29 - Extended to nine columns with Drop (rootless namespace wrapper), inserted alphabetically, with the backing, boundary, credential, and audit prose updated for nine members.
- 2026-09-29 - Cell refreshes: OpenShell maturity to the stable 0.1.x line at v0.1.2 and community to 9.7k stars with about 124 contributors, OpenSandbox community to 15.6k stars, and the OpenShell choosing bullet reworded from alpha to pre-1.0 risk after the stable graduation.
- 2026-10-02 - Cell refreshes: Agent Sandbox maturity to v1.0.5 and community to 4.1k stars, Drop maturity to v0.3.0 and community to 350 stars, ArtifactFS community to 1.2k stars, CubeSandbox community to 12.8k stars, and OpenShell community to 14.0k stars with about 126 contributors after the Open Agent Safety Platform push.
See also #
- Harness Feature Matrix - the agents these layers wrap, some with built-in sandboxing
- Codex - the built-in kernel sandboxing baseline
- Executions Feature Matrix - the unattended runs isolation exists to protect
- Control Planes Feature Matrix - governance above the sandboxes
References #
https://github.com/NVIDIA/OpenShell - the OpenShell column: protection layers, agents, alpha status
https://github.com/kubernetes-sigs/agent-sandbox - the Agent Sandbox column: CRDs, threat model, maturity
https://github.com/AxeForging/aigate - the aigate column: mechanism and its own caveats
https://github.com/withastro/flue - the Flue column: three-tier sandbox model
https://github.com/cloudflare/artifact-fs - the ArtifactFS column: FUSE architecture, limitations
https://github.com/clawkwork/clawk - the Clawk column: VM model, security limits, and release state
https://github.com/TencentCloud/CubeSandbox - the CubeSandbox column: microVM architecture, E2B compatibility, self-reported benchmarks
https://github.com/wrr/drop - the Drop column: rootless namespaces, gVisor option, TOML config
https://github.com/opensandbox-group/OpenSandbox - the OpenSandbox column: platform scope, SDKs, cosign signing, opt-in secure runtimes
https://code.claude.com/docs/en/sandboxing - the built-in sandboxing baseline the category is measured against