8.2
/ 10
1 evaluations
3.4k Downloads
Overview
Provide isolated, per-project Docker Desktop VM sandboxes for safely running agents and arbitrary code with filesystem and network controls.
Key Advantages
1.Strong isolation via lightweight VM per sandbox, reducing risk from untrusted code and destructive operations.
2.Granular outbound network controls (allowlist/denylist hosts, CIDR blocks, proxy bypass, global policy).
3.Tight integration with popular agents (Claude, Codex, Copilot, Gemini, Kiro, cagent) for secure, reproducible runs.
4.Convenient workspace mounting via virtiofs with predictable path mappings across Windows, macOS, and Linux.
5.Rich lifecycle management: create, run, exec, stop, rm, ls, reset, and save sandboxes as reusable templates for teams/CI flows.
Use Cases
- Safely exploring untrusted packages, skills, or external code before installing or executing them on the host system.
- Running arbitrary third-party or user-submitted code with reduced risk to the developer machine or CI runner.
- Isolating agent workloads that need tightly controlled or audited network access (e.g., API-allowlisted agents).
- Creating persistent, reproducible development or experimentation environments per project or team.
- Testing destructive or system-modifying operations (e.g., file deletions, privileged scripts) without touching the host filesystem.
Evaluation Scores
8.2
/ 10
Reliability
7.5
Functionality
8.7
Usability
8.2
Safety
9.0
Performance
7.8
Compatibility
7.5
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.2/103/19/2026▼
OS: darwin-x64LLM: google/gemini-3.1-pro-preview
**Quick judgement**: This skill is a robust, well-thought-out Docker Desktop–based sandboxing layer for agents and arbitrary code. It’s particularly valuable when security and isolation matter more than raw performance or deployment flexibility.
**Strengths & benefits**
- Per-sandbox VM isolation significantly reduces risk from untrusted or destructive code.
- Detailed, practical CLI interface for lifecycle management (create/run/exec/stop/rm/reset/save).
- Fine-grained outbound network controls (allow/block hosts and CIDRs, proxy policies, logging) enable strong egress restrictions.
- Good ergonomics for real workflows: persistent dev sandboxes, templates, and clear workspace mounting semantics across OSes.
- Explicit patterns for safe package exploration, locked-down agent runs, and persistent environments.
**Key risks / limitations**
- Requires Docker Desktop 4.49+ and the sandbox plugin, limiting compatibility to supported environments (no pure server/docker-engine setups).
- Some edge cases (e.g., Node.js `fetch` ignoring proxy env vars) can lead to unexpected network behavior unless the documented workarounds are applied.
- Complexity of Docker + VM + proxy setup may introduce operational friction and potential misconfiguration, especially on Windows (path conversion issues) and after Docker updates.
**Recommended scenarios**
- Use when running untrusted packages or third-party code, especially on developer machines or CI where host safety is critical.
- Use for security-focused agent workloads that need strict outbound network policies and reproducible environments.
- Use to test destructive or experimental operations in a controlled, resettable environment.
- Consider alternatives or simpler setups if you only need basic containerization, lack Docker Desktop support, or operate exclusively on headless Linux servers without the sandbox plugin.
Comments (0)
No comments yet. Be the first!