Strands Box: another open source sandbox Strands released Strands Box, an open source sandbox for AI agents that combines operating-system isolation with semantic policies written in the Dogwood policy language, currently in preview with support limited to local execution on macOS with Apple silicon. Box is harness-agnostic: users pick the agent program or binary, configure its access in box.toml, and write policies in policy.dw, with the host OS enforcing direct access restrictions and an embedded Dogwood Local Engine evaluating permit and forbid rules that deny operations by default. Strands Shell, Monty for Python, the egress gateway, and the MCP broker share one policy engine and event history, so a file read through one interpreter can cause the gateway to deny a later outbound HTTP request, and the gateway injects configured API credentials or AWS SigV4 signing so the agent never receives the underlying secrets. Strands Box is an open source sandbox for AI agents. It combines operating-system isolation with semantic policies written in Dogwood https://dogwood-policy.github.io/dogwood/ , so you can control what agents can access and the conditions under which they can act. Box is harness-agnostic. You choose the agent program or binary to run, configure its access in box.toml , and write its policies in policy.dw . The host OS enforces the direct access restrictions in box.toml . Strands Shell, Monty for Python, the egress gateway, and the MCP broker send the operations they handle to the embedded Dogwood Local Engine, which evaluates the rules in policy.dw . Box enforces its allow or deny decisions outside the agent process. Dogwood uses permit and forbid rules. Operations checked by the engine are denied by default: a matching permit must allow the operation, and a matching forbid overrides that permission. Box's interpreters and gateways share an event history, so rules can use earlier actions and elapsed time to decide what is allowed next. For example, a file read through Shell or Python can cause the gateway to deny a later outbound HTTP request. Preview: Box currently supports local execution on macOS with Apple silicon. We welcome feedback through GitHub issues https://github.com/strands-agents/box/issues . Read CONTRIBUTING.md https://github.com/strands-agents/box/blob/main/CONTRIBUTING.md before submitting a change. - File, program, and network restrictions. The agent's sandbox limits its direct access. Box reports the configured grants at startup. - Semantic and temporal policies. Dogwood rules can depend on the requested operation, its arguments, earlier actions, and elapsed time. Operations checked by the policy engine are denied unless a rule permits them. - Policy across code and tools. Strands Shell, Monty for Python, the egress gateway, and the MCP broker use one policy engine and event history. A file read through one interpreter can affect whether a later network request is allowed. - Request and tool-call checks. The egress gateway checks connections and HTTP requests, including their method and path. The MCP integration checks configured tool calls and their arguments. - Credential injection. The gateway authenticates permitted requests with configured API credentials or AWS SigV4 signing. The agent does not receive the underlying secrets. - Decision records. Box records policy decisions in OTLP JSON. By default, records go to