cd /news/ai-agents/paldron-policy-gate-and-sandbox-arou… · home › topics › ai-agents › article
[ARTICLE · art-142607] src=github.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Paldron – policy gate and sandbox around whatever your coding agent runs

Paldron, a policy gate and sandbox for commands invoked by coding agents, has released version v0.2.0 with prebuilt tarballs for Linux, macOS, and Windows on its GitHub releases page. The Go 1.24+ tool exits 0 to allow, 2 to deny, and 1 when broken, gating argv and running commands behind Landlock/seccomp and resource limits on Linux while falling back to policy gate plus output scan on macOS and Windows, where require_os_isolation = true fails closed. An optional jev_verdict setting adds one semantic judgment of captured output for secret exposure and hostile action at a default 0.7 threshold, and Paldron remains model-free with no cloud unless that key is set.

read3 min views1 publishedSep 30, 2026
Paldron – policy gate and sandbox around whatever your coding agent runs
Image: Michielbdejong (auto-discovered)

Decide whether it may run. Policy gate and sandboxed exec for commands invoked by coding agents. Exits 0 allow, 2 deny, 1 broken (same numbers as annalist gate: Annalist records what happened, Paldron decides whether it may run).

No model, no chat, no cloud.

Platform check (policy gate) exec policy + output scan OS isolation (Landlock/seccomp)
Linux x86_64 yes yes yes
Linux arm64 yes yes builds; kernel isolation untested on arm64
macOS arm64 / amd64 yes yes partial (kernel: network + credential vaults; files: policy + scan)
Windows amd64 yes yes ( require_os_isolation = false ) no — fails closed

Requesting require_os_isolation = true where no kernel backend exists (Windows) exits 1 with a clear message instead of running unisolated. Degraded mode prints a warning to stderr on every run.

Prebuilt tarballs for Linux, macOS, and Windows are on the releases page. Or build from source (requires Go 1.24+):

go install github.com/GregDixonMXN/paldron/cmd/paldron@latest
git clone https://github.com/GregDixonMXN/paldron && cd paldron && go build -o paldron ./cmd/paldron

Versioned tarballs: scripts/package.sh v0.2.0 (cross-targets via GOOS/ GOARCH, e.g. GOOS=darwin GOARCH=arm64 scripts/package.sh v0.2.0).

printf 'open(".env", "w").write("x=1\\n")\n' > src/leak.py
paldron exec --policy policy.toml -- python3 src/leak.py
  1. Copy examples/paldron-exec/policy.toml (Linux) orexamples/paldron-exec/policy.mac.toml (Mac/Windows).
  2. Run your agent command behind it: paldron exec --policy policy.toml -- <command> .
  3. Try to exfiltrate or write a secret — expect exit 2 with a reason.
allow_paths = ["src/", "docs/"]
deny_globs = [".env", ".env.*", "*.pem", "**/secrets/**"]
allow_network = false
allow_binaries = ["ls", "cat", "python3", "git"]
require_os_isolation = true
timeout_sec = 30
max_processes = 4096   # default 4096
max_memory_mb = 8192   # default 8192
max_open_files = 1024  # default 1024
cpu_time_sec = 60      # default 60
max_file_size_mb = 1024 # default 1024

Secrets are denied even with no policy file. Unknown keys are an error. exec gates argv, runs the command behind Landlock/seccomp/resource limits (Linux; policy gate + output scan elsewhere), then flips a successful run to deny if it produced a denied file (argv gating cannot see runtime writes). Flags are not paths.

paldron check --policy policy.toml -- write_file '{"path":"/abs/src/a.txt","content":"hi"}'
paldron exec  --policy policy.toml -- python3 src/tool.py
paldron schema --tool execute_code

See examples/paldron-exec/ for the composed fixture, including the Mac/Windows policy.

The file scan never sees stdout: a run that prints secrets (env, cat .env) passes it silently. With jev_verdict = true, a successful run's captured output gets one semantic judgment (secret exposure + hostile action, calibrated probabilities) before the allow:

jev_verdict = true
jev_threshold = 0.7   # deny at or above this probability (default 0.7)
jev_on_error = "deny" # "deny" (default, fail closed) or "allow"

Key from JEV_API_KEY. No key with jev_verdict set fails closed (unless jev_on_error = "allow"). Unset entirely and nothing calls out — Paldron stays model-free, no cloud, as before.

Requires Go 1.24+. go test ./.... Extracted from Reeve's guardrail + sandbox (see reeve/docs/cut.md); the registry, models, memory, and desktop stayed behind.

── more in #ai-agents 4 stories · sorted by recency
── more on @paldron 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/paldron-policy-gate-…] indexed:0 read:3min 2026-09-30 · —