{"slug": "strands-box-another-open-source-sandbox", "title": "Strands Box: another open source sandbox", "summary": "Strands released Strands Box, an open source sandbox for AI agents that combines operating-system isolation with semantic policies written in the Dogwood policy language, currently in preview with support limited to local execution on macOS with Apple silicon. Box is harness-agnostic: users pick the agent program or binary, configure its access in box.toml, and write policies in policy.dw, with the host OS enforcing direct access restrictions and an embedded Dogwood Local Engine evaluating permit and forbid rules that deny operations by default. Strands Shell, Monty for Python, the egress gateway, and the MCP broker share one policy engine and event history, so a file read through one interpreter can cause the gateway to deny a later outbound HTTP request, and the gateway injects configured API credentials or AWS SigV4 signing so the agent never receives the underlying secrets.", "body_md": "Strands Box is an open source sandbox for AI agents.\nIt combines operating-system isolation with semantic policies\nwritten in [Dogwood](https://dogwood-policy.github.io/dogwood/), so you can control\nwhat agents can access and the conditions under which they can act.\n\nBox is harness-agnostic. You choose the agent program or binary to run, configure\nits access in `box.toml`, and write its policies in `policy.dw`.\n\nThe host OS enforces the direct access restrictions in `box.toml`. Strands Shell,\nMonty for Python, the egress gateway, and the MCP broker send the operations\nthey handle to the embedded Dogwood Local Engine, which evaluates the rules in\n`policy.dw`. Box enforces its allow or deny decisions outside the agent process.\n\nDogwood uses `permit` and `forbid` rules. Operations checked by the engine are\ndenied by default: a matching `permit` must allow the operation, and a matching\n`forbid` overrides that permission.\n\nBox's interpreters and gateways share an event history, so rules can use earlier actions and elapsed time to decide what is allowed next. For example, a file read through Shell or Python can cause the gateway to deny a later outbound HTTP request.\n\n**Preview:** Box currently supports local execution on macOS with Apple silicon.\nWe welcome feedback through [GitHub issues](https://github.com/strands-agents/box/issues).\nRead [CONTRIBUTING.md](https://github.com/strands-agents/box/blob/main/CONTRIBUTING.md) before submitting a change.\n\n- **File, program, and network restrictions.** The agent's sandbox limits its\ndirect access. Box reports the configured grants at startup.\n- **Semantic and temporal policies.** Dogwood rules can depend on the requested\noperation, its arguments, earlier actions, and elapsed time. Operations checked\nby the policy engine are denied unless a rule permits them.\n- **Policy across code and tools.** Strands Shell, Monty for Python, the egress\ngateway, and the MCP broker use one policy engine and event history. A file read\nthrough one interpreter can affect whether a later network request is allowed.\n- **Request and tool-call checks.** The egress gateway checks connections and\nHTTP requests, including their method and path. The MCP integration checks\nconfigured tool calls and their arguments.\n- **Credential injection.** The gateway authenticates permitted requests with\nconfigured API credentials or AWS SigV4 signing. The agent does not receive the\nunderlying secrets.\n- **Decision records.** Box records policy decisions in OTLP JSON. By default,\nrecords go to`<box_dir>/private/telemetry/records.jsonl` .\n\nDirect filesystem grants in `box.toml` are enforced by the OS and do not produce\nindividual Dogwood decisions. To apply a policy to file operations, use the\ninterpreters and keep those files out of the agent's direct grants. See\n[filesystem access](https://github.com/strands-agents/box/blob/main/docs/user/security.md) and [policy](https://github.com/strands-agents/box/blob/main/docs/user/policy.md).\n\nBox runs the Dogwood Local Engine and its enforcement components in its own process, outside the agent's sandbox. Strands Shell, Monty, the egress gateway, and the MCP broker check operations with the engine before allowing them. They also record events that later policy decisions can use.\n\n```\nflowchart LR\n    subgraph sandbox[\"Agent OS sandbox\"]\n        agent[\"Agent application\"]\n    end\n\n    net[\"network requests\"]:::label\n    py[\"Python code\"]:::label\n    sh[\"shell commands\"]:::label\n    mc[\"local MCP calls\"]:::label\n\n    subgraph trusted[\"The box's trusted process (outside the agent sandbox)\"]\n        proxy[\"Egress gateway\"]\n        monty[\"Monty for Python\"]\n        shell[\"Strands Shell\"]\n        mcp[\"MCP broker\"]\n        policy[[\"Dogwood Local Engine and event history\"]]\n    end\n\n    agent --- net --> proxy\n    agent --- py --> monty\n    agent --- sh --> shell\n    agent --- mc --> mcp\n    proxy -->|\"policy checks\"| policy\n    monty -->|\"policy checks\"| policy\n    shell -->|\"policy checks\"| policy\n    mcp -->|\"policy checks\"| policy\n\n    classDef label fill:none,stroke:none;\n```\n\nWhen the agent uses a program such as `git` or `cargo`, or a local MCP server,\nBox checks the launch against policy and runs the program in its own sandbox.\nYou configure which files each program can read or change. The agent can send\nrequests to Box's interpreters, but external programs and local MCP servers\ncannot. Box receives their output and exit status, and their\nnetwork traffic goes through Box's gateway by default. See the\n[security model](https://github.com/strands-agents/box/blob/main/docs/user/security.md) for details.\n\nFor each part, where it runs, what it decides, and how one request moves through them, read\n[Box architecture](https://github.com/strands-agents/box/blob/main/docs/design/architecture.md).\n\nFollow the [getting-started guide](https://github.com/strands-agents/box/blob/main/docs/user/getting-started.md) to run\nStrands CLI with Box. To follow this guide, you need a Mac with Apple silicon and\nmacOS 15 or later, Node.js 22.21 or later from Homebrew, and access to Claude\nOpus 5 on Amazon Bedrock in `us-west-2`.\n\nThe download script checks the release checksum and unpacks the binaries into\n`./box-core`. It does not change your `PATH` or system directories:\n\n```\ncurl -fsSL https://raw.githubusercontent.com/strands-agents/box/main/download.sh | sh\n./box-core/box --version\n```\n\nKeep the downloaded binaries together in `./box-core`.\nYou can also [build from source](#build-from-source). Then follow the guide to\nwrite `box.toml` and `policy.dw`, and run the box.\n\nEdit `box.toml` to change the agent's environment and direct access grants. Edit\n`policy.dw` to change the rules for operations Box checks through its interpreters\nand gateways. You can give your coding agent the policy-authoring skill for help\nwith Dogwood syntax and Box's supported actions:\n\n```\nhttps://raw.githubusercontent.com/strands-agents/box/main/.agents/skills/authoring-box-policy/SKILL.md\n```\n\nRun the [Strands Python SDK example](https://github.com/strands-agents/box/blob/main/examples/strands-box/strands-sdk-agent) for a small\nagent whose three tools use Shell.\n\nSee the [example index](https://github.com/strands-agents/box/blob/main/examples/README.md) for dependencies and run instructions.\n\nThis is a Cargo workspace. `rust-toolchain.toml` pins the compiler, and rustup\ninstalls it on the first build. Build the box binaries from a clone with\n[rustup](https://rustup.rs/):\n\n```\ngit clone https://github.com/strands-agents/box.git\ncd box\ncargo build --release -p strands-box -p strands-box-containment\n```\n\nRun the compiled binary as `./target/release/strands-box`. Keep its helper\nbinaries in the same directory.\n\nCommon tasks run through [`just`](https://github.com/casey/just):\n\n```\njust build         # the CLI, the alias image, and the containment trampoline\njust test          # workspace tests\njust check         # pre-push gate: fmt-check + clippy + test\njust test-all      # workspace tests and box example checks\n```\n\n`cargo test --workspace --all-features` runs the full suite. Include\n`--all-features` to run the `box_shell` and `box_credentials` suites, which require\nthe `test-support` feature.\n\n| Guide | Contents | \n|---|---|\n| [`docs/user/`](https://github.com/strands-agents/box/blob/main/docs/user) | How to install Box and run a box. | \n| [`docs/design/`](https://github.com/strands-agents/box/blob/main/docs/design) | Architecture, enforcement boundaries, and design decisions. | \n\nSee [AGENTS.md](https://github.com/strands-agents/box/blob/main/AGENTS.md) for the repository rules and the current state.\n\nOpen an issue on this repository. For a suspected security problem, read\n[SECURITY.md](https://github.com/strands-agents/box/blob/main/SECURITY.md) first.\n\nApache License 2.0.", "url": "https://wpnews.pro/news/strands-box-another-open-source-sandbox", "canonical_source": "https://github.com/strands-agents/box/", "published_at": "2026-10-08 16:07:17+00:00", "updated_at": "2026-10-08 16:17:48.688311+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-tools", "developer-tools", "agent-protocols"], "entities": ["Strands", "Strands Box", "Dogwood", "Strands Shell", "Monty for Python", "MCP broker", "AWS SigV4", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/strands-box-another-open-source-sandbox", "markdown": "https://wpnews.pro/news/strands-box-another-open-source-sandbox.md", "text": "https://wpnews.pro/news/strands-box-another-open-source-sandbox.txt", "jsonld": "https://wpnews.pro/news/strands-box-another-open-source-sandbox.jsonld"}}