community curated · microVM agents
Awesome Docker Sandboxes kits
A searchable portal over the awesome-docker-sbx list — 180 kits, templates, wrappers, GUIs, guides and deep dives for running AI coding agents inside isolated microVMs.
180 of 180 entries
⭐ Featured Kits
A hand-picked set of kits and setups worth starting with - spanning CI/CD, databases, local-model coding agents, and per-agent isolation. Several also appear in their category sections below.
shelajev/tessl-sbx-kit
Kit that installs the Tessl CLI, injects credentials via the proxy, and wires the Tessl MCP server into the sandboxed agent.
jbradford/sbx-pi-agent
A personal setup for running the Pi agent in sbx.
ajeetraina/sbx-kits-litellm
A standalone Docker Sandboxes kit (kind: mixin) that points a sandbox agent at a LiteLLM proxy running on the host, reachable at host.docker.internal:4000.
shelajev/agy-sbx-kit
Kit for running Google's Antigravity CLI (agy) in an isolated sandbox. By a Docker DevRel.
dvdksn/sbx-kitty
sbx blueprint for the kitty terminal emulator, by a Docker employee. Good pattern reference for tooling kits.
🏛️ Official
Resources maintained by Docker.
docker/sbx-releases
The home for sbx releases, installation instructions, and issue tracking. Start here.
Docker Sandboxes Documentation
Official docs: get started, usage, agents, customize, architecture, security, CLI reference, and FAQ.
docker/sbx-kits-contrib
Community repository for sbx kits, maintained under the Docker org. Each top-level directory is a kit with a spec.yaml. Enforces verified commit signatures.
dockersamples/sbx-quickstart
Official quickstart walkthrough: mount a workspace, run an agent, work with branches, and explore the network governance panel.
Product page: Docker Sandboxes
Overview, supported agents, and install commands for macOS, Windows, and Linux.
🔧 Wrappers & CLIs
Tools that wrap sbx to streamline per-project or per-task setup. A notable pattern: several independent authors have converged on a declarative config → bootstrapped sandbox model, suggesting shared appetite for one-command setup above the base CLI.
maxkrivich/sbx-toolkit
"Dotfiles for sandboxes." Two tools - sbx-setup (run once per machine to bake in agent config, tool versions via mise, and packages) and sbx-start (one command per project, reads .sbx.toml). Shareable templates and a machine-level base image model.
HenrikPoulsen/sbxgo
Single-binary Go CLI focused on per-repo reproducibility. Commits .sbxgo/config.toml to the repo so the whole team shares one environment; supports kits/templates, drift detection, and sandbox-scoped allow/deny domains. Ships versioned binaries with SHA-256 verification. Agent-agnostic.
travisallendotdev/agentbox
TypeScript/Bun CLI focused on per-task bootstrap for Claude Code. One command (agentbox up project.yaml) injects secrets, clones repos, loads skills/plugins/hooks, runs lifecycle phases, and fires the agent with an initial prompt. Build from source.
lukehedger/sbox
Lightweight shell wrapper for launching one-off Claude Code sandboxes with opinionated defaults: branch-mode worktrees, caffeinate on macOS, Opus + --dangerously-skip-permissions, and acli/bun baked into a snapshotted template. Note: forwards Anthropic and Atlassian credentials into the sandbox via host env vars rather than the sbx credential proxy.
thewiw/docker-sbx
Tooling to install the Docker Sandboxes engine and create/manage sandboxes.
acomagu/nix-docker-sbx
A Nix flake for running Docker Sandboxes on Linux.
📦 Kits
Declarative YAML artifacts (kits) that extend a sandbox with tools, skills, credentials, and network rules at runtime. Includes vendor, Docker-team, and community kits.
docker/sbx-kits-contrib
The central community kit collection (also under Official). Reference examples for common kit patterns, plus a build-your-own-agent tutorial using the Amp kit.
dvdksn/kits-cookbook
A cookbook of example kits for sbx, by a Docker docs maintainer. Useful as a pattern reference.
dvdksn/sbx-kitty
sbx blueprint for the kitty terminal emulator, by a Docker employee. Good pattern reference for tooling kits.
kernel/docker-sbx-kit
Vendor integration from Kernel (agent browser infrastructure). Mixin kit providing the Kernel CLI, Kernel skills for Claude Code, and proxy-managed Kernel API auth - so KERNEL_API_KEY never enters the VM. A clean example of the credential-proxy pattern.
HofmeisterAn/docker-sandbox-kit
Minimal kit running the GitHub Copilot agent with .NET SDK 10 pre-installed. The host's GH_TOKEN is injected by the sandbox proxy at request time. Loadable directly via git+https:// reference.
shelajev/agy-sbx-kit
Kit for running Google's Antigravity CLI (agy) in an isolated sandbox. By a Docker DevRel.
shelajev/vibe-sbx-kit
Kit for running Mistral Vibe with MISTRAL_API_KEY injected via the host proxy.
shelajev/tessl-sbx-kit
Kit that installs the Tessl CLI and injects credentials via the proxy.
shelajev/little-coder-sbx-kit
Kit for running little-coder with Docker Model Runner.
shelajev/sbx-rtk-kit
Kit for RTK (Rust Token Killer), which reduces LLM token usage by 60-90% via context compression.
shelajev/labspace-demo-sbx-kits-dhi
Labspace wrapper for the sbx kits + Docker Hardened Images demo, featuring a host-backed ttyd provider.
mikegcoleman/sbx-data-demo
Demo kit that installs a Python data-analysis toolkit, dataset, and demo content into a sandbox.
market-dot-dev/docker-sbx-kit
Kit for Traces.
MapuH/sbx-shell-pi
Kit for running the Pi coding agent in a Docker sandbox.
natesilva/sbx-kit-npm-pnpm-hardening
Mixin kit that hardens npm/pnpm against supply-chain attacks by blocking install scripts and enforcing a 7-day release age gate on packages.
protyposis/sbx-kits
Multi-kit collection: OpenCode with OpenChamber sidecar, GitHub Copilot Enterprise auth, GitLab CLI, OpenCode Go auth, and a traffic-inspection CA (ZScaler) kit.
savoisn/sbx-kit-vibe
Independent Mistral Vibe sbx kit variant with proxy-managed credential injection.
kulla/sbx-kits
Personal kit collection, including an asdf version-manager kit.
fgervais/sbx-kit-pyocd
Kit for PyOCD (Open On-Chip Debugger) - useful for embedded/hardware development workflows inside a sandbox.
fgervais/sbx-kit-serial-console
Kit providing serial console access inside a sandbox, targeting embedded/hardware use cases.
TriticeaeToolbox/sbx-vscode
Kit that installs VSCode and the Claude Code extension into a Docker Sandbox, then creates a VSCode tunnel so you can connect your local VSCode (or a browser) directly to the sandbox.
ajeetraina/sbx-kits-mem0
Mixin kit that adds the Mem0 memory layer to any sandbox agent, pre-wired to a local Docker Model Runner (DMR) for both the LLM and the embedder. Supports OpenAI and Gemini as swappable cloud providers; credentials are proxy-managed.
ajeetraina/sbx-kits-firecrawl
Mixin kit that adds live web access to any agent via the Firecrawl Python SDK. Gives the agent the ability to search, scrape, and crawl; FIRECRAWL_API_KEY is proxy-managed.
ajeetraina/sbx-kits-nanoclaw
Sandbox kit (kind: sandbox) for NanoClaw, a Claude Code-driven AI assistant runtime. Clones and builds the upstream repo at creation time; handles OneCLI bind-address and NO_PROXY quirks specific to the sbx microVM.
ajeetraina/sbx-kits-nemoclaw
Mixin kit that installs the NVIDIA NemoClaw CLI (OpenClaw and Hermes variants) into any sbx agent. Defaults to NVIDIA Endpoints inference; the NVIDIA key is injected via a custom sbx secret binding - never baked into the spec.
ajeetraina/sbx-kits-dagger
Mixin kit that adds Dagger, a programmable containerized CI/CD engine, to any sandbox agent. Installs the Dagger CLI as the agent user and allow-lists only the egress Dagger needs; the engine provisions and runs entirely inside the sandbox's own private Docker daemon - no host access, no remote runner. Dagger Cloud is optional and off by default. (Also in Featured Kits.)
ajeetraina/sbx-kits-surrealdb
Mixin kit that embeds SurrealDB - documents, graph edges, and native vector search in one process - plus the surrealdb Python SDK into any agent. SurrealDB runs in-process and persists on disk inside the VM; vector search is pre-wired to a local Docker Model Runner embedder (swappable to OpenAI or Gemini), giving an agent semantic memory with no separate vector database. (Also in Featured Kits.)
dirien/infrastructure-sandbox-kit
Mixin kit that sets up a Claude Code sandbox for Infrastructure-as-Code work: Pulumi, Terraform, OpenTofu, and the AWS/Azure/Google Cloud CLIs (version-pinned, checksum- or signature-verified), plus language servers and an APM setup (skills, subagents, guardrail hooks, Pulumi MCP) in the agent home. The Pulumi Cloud token is proxy-managed. The same repo ships a matching template image (see Templates & Images).
🖼️ Templates & Images
Reusable template images that bake tools and configuration into a sandbox base image.
henrybravo/docker-sandbox-run-copilot
Template for running GitHub Copilot CLI in an isolated environment. One of the most-starred community templates.
geut/sbx-shell-pi
Custom template image for running Pi inside Docker Sandboxes.
nicmeriano/claude-sandbox-template
Custom Claude Code template that brings your global config (skills, statusline, etc.) into the sandbox.
holbora/dockbox
Docker sandbox template with MCP Gateway for Claude Code.
VeryEvilHumna/claude-bun-docker-sandbox
Claude template with the Bun runtime preinstalled.
ealeyner/nanoclaw-sbx-template
Template that pre-bakes NanoClaw's prerequisites (Node, pnpm, build tools).
codingforentrepreneurs/opencode-ollama-sbx-template
Template for OpenCode + Ollama.
travishathaway/docker-sandbox-claude-code-bedrock
Image for running Claude Code with Amazon Bedrock inside a sandbox.
travishathaway/docker-sandbox-opencode-bedrock
Image for running OpenCode with Amazon Bedrock inside a sandbox.
alDuncanson/hermit
Custom template for running OpenClaw via Ollama in an isolated sandbox.
pavlov-net/sbx-templates
Custom sandbox templates for sbx.
erkannt/sbx-templates
Personal collection of sbx templates.
vskh-docker-images/sandbox-templates
Custom base images for Docker sandboxes.
dlorych/docker-ai-sandbox-templates
Common sandbox templates reused across projects.
GenAI4RSE/sandbox
Enhanced Docker sandbox templates for running AI agents safely (published to Docker Hub).
shaftoe/sbx-template-pi
Template image for the Pi coding agent.
caynev/sbx-pi
Template for Pi.
trq/pi-sandbox
Minimal template for running vanilla Pi in the shell sandbox environment.
ajeetraina/sbx-mixins-template
Starter template for building mixin kits. Includes a filled spec.yaml, a no-secret example (ruff linter), a push script, and guidance on the proxy-managed credential pattern. The mem0 kit is the reference implementation.
dirien/infrastructure-sandbox-kit
Prebuilt Infrastructure-as-Code template for the claude agent with Pulumi, Terraform, OpenTofu, the cloud CLIs, and language servers baked in, so sandboxes start in seconds instead of provisioning on first create. Pair it with the kit from the same repo for the network allow-list and the proxy-managed Pulumi credential.
🖥️ GUIs & Dashboards
Graphical and desktop tools for managing sandboxes, agents, and worktrees.
mdelapenya/biomelab
Desktop GUI for managing git worktrees and coding agents running in Docker Sandboxes (sbx). One sandbox per agent per repo; real-time sandbox lifecycle controls (create/start/stop/remove), worktree cards showing branch, dirty, sync, and PR status, multi-repo dashboard, and agent detection for Claude, Kiro, Copilot, Codex, OpenCode, and Gemini.
beachead-dev/beachead
Tauri 2.0 desktop app (Rust/React) for managing Docker Sandbox microVMs. Features: Personas (agent configs), Sessions (terminal windows via xterm.js), Network Policies, and per-persona Memory backed by MCP containers in Docker. SQLite local storage.
ainova-systems/code-sandbox-console
VS Code extension (Sandbox Console on the Marketplace) that drives sbx from inside the editor: a Sandboxes tree with live status and state-gated actions, a form for agent/credentials/ports/env, and one native terminal per agent - terminal-first, no chat panel, no docker commands. Per-repo by design: the committed .sandbox/config.yaml recipe shares sandbox definitions across the team while a git-ignored local id keeps clones and worktrees conflict-free; custom environments go Dockerfile → docker build → sbx template load. Secrets are piped over stdin to sbx secret set (OS keychain) and never reach the repo, an image, or an env var. Agent-agnostic - the agent list is discovered from your sbx. Also generates a sbx.sh project CLI so shells and agent skills reuse the same naming and lifecycle rules.
🤖 Agent-Specific Setups
Personal and project setups focused on a particular agent or environment.
alexdaiii/claude-agent-sbx
Running Claude Code inside Docker Sandboxes with ACP for JetBrains.
jbradford/sbx-pi-agent
A personal setup for running the Pi agent in sbx.
TheTipTapTyper/little-coder-sbx-setup
Setup for running the little-coder AI coding agent with a local LLM.
fieryWalrus1002/homelab-pi-sbx
Getting pi.dev working in sbx on Ubuntu 24.04.
wluberti/sandbox
Project to run agentic agents and harnesses in sbx.
cuolm/pi-sbx-llamacpp
Run the Pi coding agent in a Docker Sandbox microVM with a local llama-server as inference backend. Includes architecture diagram, spec.yaml, and models.json for provider config.
wireless25/crush-sandbox
Docker sandbox for the Crush CLI (Charmbracelet) with Git worktree support for multi-branch parallel agent work and per-workspace persistent caching.
mikeatlas/omp-sbx
Full setup for running the oh-my-pi (omp) coding agent in a Docker sbx microVM. Shares ~/.omp state across restarts, supports parallel worktree-based sandboxes, ships LSP servers, and replaces Puppeteer with a native Rust browser CLI to work around sbx's Chromium constraints.
cdr-chakotay/sbx-mistral
Docker sandbox for running Mistral Vibe CLI in full isolation. Launches in YOLO mode (auto-approve) by default; switch to confirmation-based modes via Shift+Tab for more controlled execution.
🔐 Security & Demos
Projects exploring the security boundary, threat models, and isolation guarantees of sbx - relevant given the product's core purpose.
zickgraf-ai/agentic-press
Reference architecture for secure agentic AI development: MCP injection filtering, audit logging, and more.
kiview/you-gotta-keep-the-dogs-away
Demo code for the JCon 2026 talk "You Gotta Keep the Dogs Away" - sandboxing a malicious MCP server.
sebbmn/secure-hermes-sandbox
Hermes agent in sbx with a web-search proxy sanitizer and Firecrawl.
📚 Guides & Tutorials
Step-by-step, task-focused walkthroughs.
Get started with Docker Sandboxes
Official first-session guide: install, authenticate, run, branch modes, and cleanup.
Customizing sandboxes
How templates and kits work and when to use each.
Build your own agent kit
Walkthrough of building an agent kit (using Amp) from base-image choice to invocation.
Run Claude Code in a Docker Sandbox with Docker Model Runner
Point Claude Code at a local model served by Docker Model Runner via ANTHROPIC_BASE_URL and a policy rule.
Customized templates with Docker sandbox
Andrew Lock on building custom templates: adding tools to the default base, or layering sbx tooling onto a different base image.
ajeetraina/labspace-sbx
Interactive lab for learning Docker Sandboxes: starts a local ttyd terminal alongside step-by-step instructions covering microVM isolation, credential proxy, network policy, git worktrees, parallel agents, Docker Model Runner, and enterprise governance.
📰 Articles & Deep Dives
Opinion, analysis, and hands-on reports.
A New Approach for Coding Agent Safety
Launch post: the problem with running agents in containers vs. microVMs, the four-layer security model, and the roadmap. (Nov 2025)
Highlights from AWS re:Invent: Supercharging Kiro with Docker Sandboxes and MCP Catalog
How the Kiro agent integrates with sbx and the MCP Catalog. By Michael Irwin. (Dec 2025)
Docker Sandboxes: Run Claude Code and Other Coding Agents Unsupervised (but Safely)
Product deep-dive: YOLO mode, the credential proxy pattern, network policies, and git branch mode. (Jan 2026)
Running NanoClaw in a Docker Shell Sandbox
Walkthrough of running NanoClaw via sbx shell, by Oleg Selajev. (Feb 2026)
Run OpenClaw Securely in Docker Sandboxes
How to use OpenClaw inside sbx with credential isolation. (Feb 2026)
Secure Agent Execution with NanoClaw and Docker Sandboxes
Deeper look at agent security with NanoClaw; covers template customization and policy rules. (Mar 2026)
Building AI Teams: How Docker Sandboxes and Docker Agent Transform Development
Docker Captains Esteban Maya Cadavid and Marco Franzon on orchestrating multiple coding agents with sbx and Docker Agent. (Mar 2026)
A Virtual Agent Team at Docker: How the Coding Agent Sandboxes Team Uses a Fleet of Agents to Ship Faster
Inside look at how the sbx team uses their own product to parallelize development across branches. By Manuel de la Peña. (May 2026)
Comparing Different Approaches to Sandboxing
Docker Captain Siri Varma Vegiraju compares container isolation, microVMs, and managed sandbox APIs on trust boundary, cold start, and persistence. (May 2026)
Docker AI Governance: Unlock Agent Autonomy, Safely
How sbx network policies, the credential proxy, and audit logging compose into a governance layer for agentic AI. (May 2026)
Coding Agent Horror Stories: The Security Crisis Threatening Developer Infrastructure
Ajeet Raina on real-world credential leak and supply-chain incidents from running agents without proper isolation. (May 2026)
The Untrusted Autonomous Workload: How AI Coding Agents Reshape What Isolation Has to Do
Docker Captain Vladimir Mikhalev on the threat model of agentic workloads and why process-level isolation isn't enough. (May 2026)
Coding Agent Horror Stories: The rm -rf ~/ Incident
Second in Ajeet Raina's horror stories series: file-system destruction when agents run without a safety boundary. (Jun 2026)
How to Secure AI Agents: A Practical Overview for Development Teams
Srini Sekaran on the full spectrum of controls: network, credential, filesystem, and process isolation in practice. (Jun 2026)
Stop Running Agents in Containers. Run Them in MicroVMs with Docker sbx
A hands-on tour of the full sbx experience: install, auth, shell sandbox, Claude Code sandbox, and port publishing, focused on the container-vs-microVM trust boundary.
Docker Sandboxes: Running AI Agents in YOLO Mode, Safely
Matteo Bisi installs, breaks, fixes, and runs GitHub Copilot CLI inside a sandbox on an M4 MacBook - verifying the security claims hands-on, including real-world policy workarounds.
Running AI agents safely in a microVM using Docker sandbox
Andrew Lock on network policies, direct vs. branch git modes, and the practical implications of --dangerously-skip-permissions.
Docker Sandboxes (sbx) Quick Start
The three workflow patterns that separate "tried it once" from "use it daily," including non-interactive prompt runs.
How Safe Is Docker Sandbox? Testing AI Agents with Java
Johannes Rabauer and Kevin Wittek (Docker) put sbx through its paces against a deliberately vulnerable Java/Maven project designed to leak credentials - covering credential proxying, Docker-in-Docker (Testcontainers), port forwarding, and local LLMs via Docker Model Runner.
🎥 Videos & Talks
Recorded demos, conference talks, live sessions, and walkthroughs.
🔍 Background & Comparisons
Context on the architecture and how sbx compares to alternatives.
Architecture | Docker Docs
How sandboxes work under the hood: microVM isolation, workspace mounting via filesystem passthrough, storage, networking, and lifecycle.
Docker Sandbox: Running AI Agents in Isolated Docker Environments
A technical comparison of container isolation vs. sbx's microVM model, the four-layer security model, and how managed sandbox APIs compare on cold start, persistence, and pricing.
🐳 Docker Sandboxes Related Stuff
Adjacent Docker resources commonly used with Docker Sandboxes.
🔎 Recently discovered (auto-added, unreviewed)
opscart/docker-sandbox-devops
Hands-on exploration of Docker Sandboxes - labs, architecture notes, threat model, and DevOps templates for running AI coding agents in isolated microVMs. _Maturity: 0⭐, no releases. Security: proxy. Auto-added 2026-05-25, unreviewed._
bouli/sbx-cline
A collection of scripts to use cline in docker sandbox. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-25, unreviewed._
shelajev/lapdog-sbx-kit
Docker Sandboxes kit that installs Datadog Lapdog and transparently wraps the sandbox's claude binary so every LLM session is captured locally (and optionally forwarded to Datadog LLM Observability). _Maturity: 0⭐, no releases. Security: proxy. Auto-added 2026-05-25, unreviewed._
kantegamartin/sbx-claude
Containerizing Claude with Docker Sandbox. _Maturity: 0⭐, no releases. Security: proxy. Auto-added 2026-05-25, unreviewed._
AlekseiKanash/bal-sbx
Sandboxing tools for LLM agents. _Maturity: 0⭐, no releases. Security: host-env creds. Auto-added 2026-05-25, unreviewed._
ThiagoCarmona/claude-pg-devcontainer
Dev Container for Claude: Claude Code + embedded PostgreSQL + MCPs + dev toolkit. _Maturity: 0⭐, no releases. Security: host-env creds. Auto-added 2026-06-02, unreviewed._
nick22985/sbx
Sandboxed Docker dev environments with multiple language/runtime presets (npm, bun, rust, java, and more). _Maturity: 0⭐, 5 release(s). Security: n/a. Auto-added 2026-06-02, unreviewed._
CauldronDevelopmentLLC/sbx
A tool for easily sandboxing applications in Linux. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-06-02, unreviewed._
SamirSaidani/sbx-claude-kit
Docker sbx mixin kit for Claude Code: persistent settings.json + PulseAudio tunnel for audio/voice mode. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
kevbot-git/sandbox-kits
A collection of reusable kits for Docker's sbx. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
la-test/sbx1-upptime
Sandbox to test and learn Upptime template. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
baby-whales-pod/sbx-claude-code-minio
Setup for running Claude Code in Docker Sandboxes with MinIO integration. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
wmeints/sbx-tooling
My personal customizations for Docker Sandboxes. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
kevbot-git/sandboxd
Sandbox'd: A light wrapper over Docker's sbx, with quality of life improvements and a kits manager. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
lucatume/sbc
Docker sbx sandbox system wrapper aimed at Claude Code. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
saharshbhansali/docker-sbx-flake
A flake that packages docker-sandboxes. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
typisttech/sbx-kits
Collection of reusable kits for Docker Sandboxes. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-05-30, unreviewed._
ajeetraina/awesome-docker-sbx
A curated list of tools, kits, templates, integrations, and resources for Docker Sandboxes (sbx) running AI coding agents in isolated microVMs. _Maturity: 2⭐, no releases. Security: n/a. Auto-added 2026-05-29, unreviewed._
aescalera-defenseunicorns/uds-sbx-kit
a kit for docker sbx that has uds, uds-mcp, and some common tools. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
agent-receipts/obsigna-examples
Clone-and-run demo: an opencode agent in a Docker sbx microVM, with cryptographically signed receipts for every tool call. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
ajeetraina/sbx-kits-vscode
Docker sbx kits for VS Code. _Maturity: 1⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
alexdaiii/slopify
Docker sandbox kits to help slopify a code base. _Maturity: 1⭐, 2 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
ChristianMoesl/pi-sbx
Run Pi coding-agent tool calls inside Docker sbx sandboxes. _Maturity: 0⭐, 2 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
copriso/docker-sbx-with-profiles
A single bash script that provisions Docker Sandboxes from named profiles - network policy, sandbox-scoped secrets, MCP servers and an in-VM repo clone, all applied before the agent attaches. Keeps work and personal Claude accounts fully separate. _Maturity: 0⭐, no releases. Security: proxy. Auto-added 2026-08-04, unreviewed._
Danstiv/sbx-dotfiles
Personal dotfiles and image build for running Claude Code in Docker Sandbox (sbx). _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
DockerSolutionsEngineering/ai.gov.sbx-template-and-kit
SBX Template + Kit to run a Web IDE + Docker Agent + local LLM. _Maturity: 1⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
DockerSolutionsEngineering/ai.gov.sbx-template-kit-docker-agent
Demo pairing an sbx template that installs a pinned docker-agent with a kit that adds a Go CLI toolchain. _Maturity: 1⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
DockerSolutionsEngineering/sbx-ide
IDE-in-sandbox toolkit: open Curso, VS Code, or Codex inside a Docker Sandbox, safely (sbx-ide). _Maturity: 1⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
DockerSolutionsEngineering/sbx-with-zed
Bridge Docker Sandboxes (sbx) to the Agent Client Protocol (ACP) so editors like Zed, JetBrains, and VS Code can drive a sandboxed Claude agent against the current repo. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
donaldgray/claude_sbx
Templates for using Docker sbx with Claude Code. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
eycjur/agentsb
CLI for running Claude Code, Codex, and other agents in per-directory microVM sandboxes, backed by Docker Sandboxes (sbx). _Maturity: 0⭐, 1 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
freecoder/sbx-oc-rust
Docker sbx template for OpenCode with a Rust toolchain. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
freecoder/sbx-pi-rust
Docker sbx template for the Pi (pi.dev) agent with a Rust toolchain. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
holon-technologies/sbx-kits
Public Docker Sandbox kits for Holon Technologies. _Maturity: 0⭐, 3 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
humphrey/sand
A tiny CLI that manages git worktrees and Docker Sandboxes (sbx) for parallel AI coding sessions. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
itbm/sbx-sdk
A SDK for Docker AI Sandboxes (sbx). _Maturity: 0⭐, 1 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
jamessawle/sbx-kits
Reusable Docker Sandbox (sbx) kits for running coding agents in isolated environments. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
jrhender/sbx-claude-code-rc-shim
Shim for the "Remote Control" Claude Code feature in an Docker sbx VM. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
karanverma/sbx-ai-eval-kit
AI Evaluation Mixin Kit for Docker Sandboxes (SBX). Run reproducible, isolated evaluation, benchmarking, and testing workflows for AI agents and models. _Maturity: 0⭐, 4 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
krisfoster/sbx-claude
Launch Claude Code inside a Docker sbx sandbox with per-project MCP servers and speckit baked in. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
krisfoster/sbx-with-zed
ACP wrapper letting ACP editors (Zed, JetBrains, VS Code) drive Docker Sandboxes (sbx) running Claude. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
Leoo0x1/pi-leo-sbx
Custom docker sbx kit for Pi. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
manuelseeger/sandcastle-sbx
Docker sbx sandbox provider for sandcastle. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
mechanoid/sbx-kit-claude-deno
Docker Sandbox kit for running Claude Code with the Deno runtime (inferred from repo name; README is empty). _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
mikesir87/sbx-kit-cloudflare-dns
A Docker Sandbox kit that provides an agent skill and credential support for Cloudflare-managed DNS. _Maturity: 0⭐, no releases. Security: proxy. Auto-added 2026-08-04, unreviewed._
mikesir87/sbx-kit-youtube-analyzer
A Docker Sandbox kit used to fetch and analyze YouTube comments for product feedback. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
N4si/sbx-kits
Docker Sandbox Kits for YugabyteDB and Meko agents. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
natesilva/sbx-kit-uvx
Docker Sandboxes (sbx) mixin kit that installs Astral uv, so a sandboxed agent can run Python tools from PyPI with uvx. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
nmarcetic/omp-sandbox
Run the omp (oh-my-pi) agent inside a hardened Docker sbx microVM. _Maturity: 1⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
praialabs/sbx-kits
Custom Docker Sandboxes Kits. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
rberrelleza/okteto-kit
Docker Sandboxes Kit for Okteto. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
shelajev/adhd-sbx-kit
Docker Sandboxes kit: installs the ADHD parallel-divergent-ideation skill for any agent (Claude Code, Codex, Gemini CLI, Cursor, …). _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
shelajev/apm-sbx-kit
Docker Sandboxes kit that installs Microsoft's APM (Agent Package Manager) CLI and resolves the workspace apm.yml on boot. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
shelajev/beads-sbx-kit
Docker Sandboxes kit: installs the Beads (bd) graph issue tracker and wires the Claude Code prime hook so the sandboxed agent boots with its task graph in context. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
shelajev/beans-sbx-kit
Docker Sandbox kit: installs hmans/beans and wires 'beans prime' into Claude Code hooks so the agent starts each session with the project's open work. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
shelajev/sbx-moderne-kit
Docker Sandboxes kit for the Moderne CLI. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
squall-chua/sbx-go-sdk
A Go SDK for automating Docker Sandboxes (sbx) - isolated micro-VM environments provisioned for AI coding agents. Drive sandbox creation, command execution, interactive agent sessions, file transfer, ports, templates, network policy, and the daemon itself, all from Go. _Maturity: 0⭐, 9 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
squall-chua/sbx-swarm-node
A decentralized control plane for Docker sandboxes. Each node wraps one host's local sbx sandbox daemon and gossips with its peers to place and manage sandboxes across the fleet - there is no central controller, no master, no external database. _Maturity: 1⭐, 8 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
stone/sbx-templates
Dev-container images for the Docker sandbox (sbx), built with buildx bake and tested with goss/dgoss. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
thenickfish/docker-ai-sbx
Custom sbx templates for AI coding agents, bundling rtk, caveman, and devbox. _Maturity: 1⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
thenvoi/jam-sandbox-kits
Docker Sandbox kits and mixins for Jam-owned agent runtimes. _Maturity: 0⭐, 15 release(s). Security: n/a. Auto-added 2026-08-04, unreviewed._
tkonsta/docker-sbx-claude-with-intellij-mcp
Creates a Docker Sandbox template for Claude Code including the MCP server for IntelliJ and a CLAUDE.md which tells Claude to use that MCP server to understand the code. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
trevorjoesmith/sbx-ask-data
sbx mixin kit: Snowflake analytics + Google Drive output for customer work, using the claude.ai snowflake-sql MCP connector and the hivemind /ask-data skill. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
TriticeaeToolbox/sbx-bb-templates
A Docker Sandbox kit that installs the generate-breedbase-templates plugin and useful python modules. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
tschuba/code-cage
Secure sandbox launcher for AI coding agents (Claude Code, pi) via Docker sbx. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
Warfront1/ares-ollama-cloud-docker-sbx
Template that runs the Ares agent with Ollama Cloud as the LLM provider. _Maturity: 1⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
Warfront1/catcode-ollama-cloud-docker-sbx
Template that runs Catalyst Code (catcode) with Ollama Cloud as the LLM provider. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
Warfront1/junie-docker-sbx
Template that runs JetBrains' Junie CLI with usage-based billing via a JUNIE_API_KEY. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
Warfront1/opencode-custom-provider-docker-sbx
Template for OpenCode with configurable OpenAI-compatible providers and ready-to-use provider kits. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
Warfront1/opencode-ollama-cloud-docker-sbx
Securely run OpenCode AI agents with Ollama Cloud in a Docker Sandbox. _Maturity: 2⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._
ypxing/docker-sbx-kits
Sandbox templates for AI coding agents (Claude, Copilot) with composable kits. _Maturity: 0⭐, no releases. Security: n/a. Auto-added 2026-08-04, unreviewed._