
Quicksand gives AI agents a full Linux virtual machine on your own hardware, controlled through an async Python API. It's for developers who need agents to execute code or interact with a desktop inside a separate operating system. Each sandbox has its own kernel and uses QEMU for hypervisor-level isolation.
It runs on macOS, Linux, and Windows, supports x86_64 and ARM64, and can use hardware acceleration. It doesn't require root privileges, Docker, or a cloud account. The Python project is open source under the MIT license.
Sandboxes start with networking disabled. You can allow internet access and forward ports when a task needs them, while host directory sharing lets agents work with selected files. Multiple agents can have separate Linux user accounts within one VM.
For code execution, the API runs shell commands and returns their output, errors, and exit status. Checkpoints capture the full VM state so an agent's changes can be rolled back after a failed operation. You can also save disk state and load it later, including on another machine.
Prebuilt images cover Ubuntu and Alpine, with headless environments for command-line tasks and Xfce4 desktops for graphical work. Desktop control includes screenshots, typing, clicks, and mouse movement. The Ubuntu desktop includes Firefox; the Alpine desktop includes Chromium. Agent-focused images include Python development tools, while a computer-use image adds Playwright and browser access through noVNC.
Claim this page and we'll verify you by hand. Quicksand gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find Quicksand?Promote it
Something wrong or outdated on this page?
1.3KUpdated 3 weeks agoMIT
macOS · Windows · Linux#Code execution#Guardrails#MCP
Reverify is a local verification toolkit for developers and reverse engineers who use AI to analyze binaries or rewrite code. It checks a model's claims against the actual file or executed behavior, then returns a verdict with evidence. The Python project is open source under the MIT license and runs on Linux, Windows and macOS as a CLI or MCP server.
1.4KUpdated 7 months agoApache-2.0
macOS · Windows · Linux · Docker · Web#Agent Skills#Code execution#Git integration
27.6KUpdated 1 day agoMIT
macOS · Windows · Linux#Code execution#MCP#Tool calling
6.1KUpdated 12 hours agoApache-2.0
macOS · Windows · Linux · Web#Git integration#Human approval#Multi-agent workflows
LoopX is a local-first, open-source control plane for people running coding, research or personal AI agents over work that lasts beyond a single session. It keeps goals, decisions and evidence intact when an agent stops, hands off work or resumes elsewhere. Your existing runtime supplies the model and tools; LoopX tracks the work and the decisions that govern its continuation.
4.3KUpdated 1 day agoApache-2.0
macOS · Windows · Linux#Code execution#Guardrails#Human approval
13.7KUpdated 8 hours agoApache-2.0
macOS · Windows · Linux · Docker#Agent Skills#Code execution#Guardrails
OpenShell is a self-hosted runtime for teams running autonomous AI agents that need access to files, APIs and credentials. It runs agents in sandboxes with kernel-level isolation and explicit access policies. It's open source under Apache 2.0 and supports Linux and macOS on Apple Silicon, with Docker, Podman or host virtualization.
Claw-Empire is a self-hosted AI agent manager that presents collaborative work as a pixel-art office. It's for developers and other people who want to delegate projects to several agents, assign department roles and review their output in one place. The office view shows agents working and meeting, while a Kanban board tracks tasks through completion.
Cua gives AI agents access to computers they can inspect and operate, with tools for desktop automation, local virtual machines, and hosted fleets. It's for developers building agents that work across native apps and browsers, or evaluating how well those agents complete computer tasks. You bring the agent and model.
nono is an open-source security runtime for people running terminal AI agents on their own machines or servers. It limits what an agent and each tool it calls can access, with boundaries enforced by the operating system. It runs on macOS, Linux and Windows through WSL2, without requiring a container, VM or daemon.