
Gondolin is a local sandbox for developers whose AI agents execute generated code and need access to files or external APIs. It runs that code inside disposable Linux micro-VMs on macOS or Linux, while the host controls network access, credentials and filesystem behavior. It's open source under Apache 2.0.
Its secret handling lets an agent call an authenticated API without receiving the real credential. The guest sees a placeholder token; the host substitutes the secret only for allowed destinations. HTTP and TLS policies can restrict outgoing requests and apply request or response hooks. Calls to external APIs still leave the machine through the permitted connections.
The network stack and virtual filesystem are implemented in JavaScript, so developers can define access policies and custom filesystem behavior in the same language as their agent tooling. QEMU is the default VM backend. A CLI and TypeScript SDK support command execution, shell access to running VMs and host-driven file operations. A Pi extension runs Pi tools inside a micro-VM with the project mounted into the guest.
For workloads that need more than a disposable shell, Gondolin supports disk checkpoints with resume, custom guest images and exposing guest HTTP services on the host. SSH provides access to the guest, with optional allowlisted outgoing SSH connections.
Claim this page and we'll verify you by hand. Gondolin gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find Gondolin?Promote it
Something wrong or outdated on this page?
1.3KUpdated 20 hours agoGPL-3.0
macOS · Linux#Code execution#Git integration#Guardrails
ai-jail puts AI coding agents such as Claude Code inside a local operating system sandbox. It's for developers who want an agent to work on a project while limiting its access to the rest of their machine. Written in Rust and licensed under GPL-3.0, it runs on Linux and macOS; Windows users need WSL2 with the Linux backend.
667Updated 2 days agoApache-2.0
macOS · Linux#Agent Skills#Browser automation#Code execution
4.3KUpdated 7 hours agoApache-2.0
macOS · Windows · Linux#Code execution#Guardrails#Human approval
13.7KUpdated 10 hours agoApache-2.0
macOS · Windows · Linux · Docker#Agent Skills#Code execution#Guardrails
OpenShell is a self-hosted runtime for teams running autonomous AI agents that need access to files, APIs and credentials. It runs agents in sandboxes with kernel-level isolation and explicit access policies. It's open source under Apache 2.0 and supports Linux and macOS on Apple Silicon, with Docker, Podman or host virtualization.
1.3KUpdated 4 weeks agoMIT
macOS · Windows · Linux#Code execution#Guardrails#MCP
1.8KUpdated 3 months agoApache-2.0
macOS · Windows · Linux · Docker#Agent Client Protocol#Code execution#Guardrails
h5i is a local, open-source toolkit that gives your AI agent browser automation and direct HTTP control for testing web applications you own or are authorized to assess. It's for teams that want an agent to investigate security flaws, with recorded evidence they can review, even without a dedicated security specialist.
nono is an open-source security runtime for people running terminal AI agents on their own machines or servers. It limits what an agent and each tool it calls can access, with boundaries enforced by the operating system. It runs on macOS, Linux and Windows through WSL2, without requiring a container, VM or daemon.
Reverify is a local verification toolkit for developers and reverse engineers who use AI to analyze binaries or rewrite code. It checks a model's claims against the actual file or executed behavior, then returns a verdict with evidence. The Python project is open source under the MIT license and runs on Linux, Windows and macOS as a CLI or MCP server.
Stakpak is an open source AI agent for developers and DevOps teams who want to run production operations on their own machines or servers. It can work interactively in a terminal or run continuously in the background, investigating app health problems, taking corrective action and notifying a human when it needs help.