# BoxLite ranks #1 of 10 AI sandboxes on HVTracker's trust score

> Source: <https://blog.boxlite.ai/boxlite-ranks-first-hvtracker-ai-sandboxes>
> Published: 2026-10-03 15:08:15.950241+00:00

On October 3, 2026, BoxLite ranked first of the ten projects in HVTracker's Sandboxes & Runtimes category, with an HVTrust score of 85.6. It was the only sandbox with an A grade, ahead of E2B (78.2) and NVIDIA's OpenShell (73.6).

*Source: [hvtracker.net, Sandboxes & Runtimes](https://hvtracker.net/?cat=Sandboxes+%26+Runtimes), updated 2026-10-03 12:10 UTC.*

[HVTracker](https://hvtracker.net) scores open-source AI agent projects on public, checkable signals, and doesn't take vendor claims into account. HVTrust is weighted toward the signals that are hardest to fake: build provenance, signed commits and the OSSF Scorecard. Maintenance and adoption make up the rest.

In other words, it answers one question about a sandbox: **can you trust the package you install?** That matters more for a sandbox than for most software. A sandbox is the one thing you install specifically to run code you don't trust, and if the package itself is compromised, the isolation it promises doesn't matter. It's usually easier to poison a release than to break a hypervisor.

| Rank | Project | HVTrust | Grade | Build provenance | Signed commits | 
|---|---|---|---|---|---|
| 1 | BoxLite | 85.6 | A | npm and PyPI | 100% | 
| 2 | E2B | 78.2 | B | none | 81% | 
| 3 | OpenShell | 73.6 | B | none | 100% | 
| 4 | OpenSandbox | 71.5 | B | none | 7% | 
| 5 | Cube Sandbox | 71.1 | B | none | 79% | 

The other five scored below 60. Scores are recomputed daily, so these will move.

The gap comes from one signal: **BoxLite is the only one of the ten that publishes build provenance.** Our npm and PyPI releases carry a signed attestation that links each package to the commit and the CI run that built it, and both registries point back to the repository HVTracker tracks. That earns the full 18 points for identity. Every other sandbox in the category scored 10.8.

It isn't popularity. E2B has six times our GitHub stars and about sixty times our weekly downloads, and adoption is 20% of the score. BoxLite still ranks higher, because the signals that are hardest to fake outweigh it.

The score isn't perfect, and the breakdown is public. Our [OSSF Scorecard](https://scorecard.dev/viewer/?uri=github.com/boxlite-ai/boxlite) is 5.2 out of 10, lower than E2B's 6.9 and OpenShell's 6.5. The checks pulling it down are ones we can fix: pinning CI dependencies by hash, scoping workflow token permissions, signing GitHub releases and adding fuzzing. We're working through them, and the score will show it.

HVTrust is one input, not a verdict. It measures how a project is built and shipped. It doesn't measure whether the isolation boundary holds, and it can't see how you deploy it. When you evaluate a sandbox, ask both questions:

HVTracker's data is a public answer to the second question. BoxLite's answer to the first has been the same since its first commit: every box is a real virtual machine with its own Linux kernel, isolated in hardware by KVM on Linux and Hypervisor.framework on macOS. A container shares the host kernel, so a container escape lands in the same kernel as everything else on the machine. Escaping a VM is a different class of attack.

BoxLite ships as an Apache 2.0 runtime you embed in your own program, with no daemon and no control plane, and as [BoxLite Cloud](https://boxlite.ai), which runs the same boxes behind an API key. Both share one SDK.

```
pip install boxlite
python
import asyncio
import boxlite

async def main():
    async with boxlite.SimpleBox(image="python:slim") as box:
        result = await box.exec("python", "-c", "print(2 + 2)")
        print(result.stdout)  # "4"

asyncio.run(main())
```


