Strands Box
Strands Box is an Apache-2.0 open-source sandbox engine for AI agents. It is aimed at the uncomfortable gap between an agent that can call tools and an operator who needs to constrain what those calls can reach. Rather than tying the runtime to one agent framework, Box runs a chosen agent program inside operating-system isolation and applies additional policy checks outside that process.
The repository describes Box as a preview for local execution on Apple-silicon Macs. That constraint is important: it is an early developer security tool, not a portable production sandbox to assume works across every platform.
What it controls
Box separates controls into two layers. box.toml grants direct filesystem access before the workload starts, and macOS enforces those limits. policy.dw uses the Dogwood policy language for actions that go through Box's trusted components: Strands Shell, Monty for Python, an egress gateway, and an MCP broker. Those policy-mediated operations default to deny, so a matching permit rule is needed and a forbid rule overrides it.
That split supports a concrete workflow: let a coding agent read a checked-out repository, route its HTTP calls through the egress gateway, and allow only named API endpoints. The gateway can attach configured credentials or AWS SigV4 after a request is allowed, keeping the underlying secret out of the agent process. The MCP broker can similarly evaluate configured tool calls and arguments.
An event history connects the components. A policy can make a later network request depend on an earlier action, such as a file read made through the managed shell or Python interpreter. Box also writes policy decision records as OTLP JSON, which gives an operator material to inspect after an agent run.
Getting started
The official quick start currently requires an Apple-silicon Mac running macOS 15 or later, Homebrew Node.js 22.21 or later, and Claude Opus 5 access through Amazon Bedrock in us-west-2. The project supplies a checksum-verifying download script:
curl -fsSL https://raw.githubusercontent.com/strands-agents/box/main/download.sh | sh
./box-core/box --version
Keep the downloaded binaries together, then define the environment and direct grants in box.toml and the mediated rules in policy.dw. Start with narrow paths and destinations, run a small agent task, and read the decision log before broadening a rule.
Limits and security notes
Box is not a substitute for reviewing its configuration. Direct paths granted in box.toml do not create per-operation policy decisions. Broad policy reads can reach sensitive paths, so the project's own security guide recommends path conditions. Cloud metadata protection also requires explicit policy rules; it is not automatic. Finally, a policy only governs operations that use Box's managed components, so tools that bypass them are outside that layer's decision log.
Alternatives
- E2B is a hosted sandbox option for code execution.
- Daytona provides development environments for agent workloads.
- Strands Harness supplies an agent harness, while Box focuses on constraining execution.
Conclusion
Use Strands Box when a local agent needs a reviewable boundary around files, tools, network requests, and MCP calls. Its useful distinction is policy enforcement outside the agent process, but its preview status and platform scope mean teams should validate their own threat model and configuration before relying on it.
Comments
No comments yet. Be the first to comment!
Related Tools
Related Insights
Stop Cramming AI Assistants into Chat Boxes: Clawdbot Picked the Wrong Battlefield
Clawdbot is convenient, but putting it inside Slack or Discord was the wrong design choice from day one. Chat tools are not for operating tasks, and AI isn't for chatting.

Grok Bot and Hermes Bot: one person finally gets a think tank and a secretariat
Grok Bot now ships with Cursor Pro+. Hermes Bot runs on a VPS. They are not smarter chat boxes. The think tank advises, the secretariat executes, and you still make the call.

Anthropic Subagent: The Multi-Agent Architecture Revolution
Deep dive into Anthropic multi-agent architecture design. Learn how Subagents break through context window limitations, achieve 90% performance improvements, and real-world applications in Claude Code.