AWS released Strands Box, an open-source sandbox for AI agents
AWS Strands Agents published Strands Box, an Apache-2.0 Rust sandbox that runs an AI agent under operating-system isolation plus a semantic Dogwood policy, with a gateway that injects API credentials outside the agent process.
Image: GitHub
Why it mattersA team running a coding agent on real work gets one enforcement point that covers shell commands, Python code, outbound HTTP and MCP tool calls, so an injected instruction cannot cause the agent to perform an action the file and network rules forbid.
Running an AI agent on a real codebase means handing it a shell, a Python interpreter, a network, and a set of API keys, and hoping it only does the work it was asked to do. A new open-source project from AWS Strands Agents replaces that hope with rules the operating system itself enforces.
Strands Box reached 213 stars in six days on GitHub, under Apache-2.0, written in Rust. The repository was created on 2 October 2026. The README calls it a preview and says macOS on Apple silicon is the supported platform today, with Linux planned.
What Box encloses
The agent runs inside an operating-system sandbox. Direct access to files, programs and the network is listed in a box.toml file, and the OS enforces those grants itself. Alongside that, Box runs four small programs outside the agent that proxy everything the agent asks to do: Strands Shell for shell commands, Monty for Python, an egress gateway for outbound HTTP, and an MCP broker for local MCP tool calls. Each call is checked by a policy engine named Dogwood before it runs.
Dogwood is a policy language with permit and forbid rules. Operations the engine sees are denied by default: a matching permit has to allow a request, and a matching forbid overrides that permission. Rules can read the arguments, the earlier actions in the session, and the elapsed time, so a file read through the Python interpreter can be used by a later rule to deny an outbound HTTP request.
Credentials stay out of the agent
The egress gateway signs permitted requests with the API keys the user configured, including AWS SigV4. The agent itself does not receive the underlying secrets. Combined with the OS sandbox, a leaked token inside the agent context does not reach a usable key, because the key never passed through the agent process. Every policy decision is written to a JSON Lines file in OTLP format for later audit.
Who it is for
A developer running a coding agent on an unfamiliar repository, a team letting an agent file pull requests overnight, or anyone who runs model-generated shell commands at all gets one place to list what the agent is allowed to access and a log of what it did. Box works with any coding agent the user picks: the same box.toml and policy.dw apply whether the inner program is Strands' own CLI, Claude Opus running through Amazon Bedrock, or another coding harness.
Box's addition to the existing agent-sandbox tools is the policy engine added to OS containment, together with the credential injection that keeps secrets outside the agent. OS isolation on its own decides which files and ports are reachable at all. The Dogwood engine then decides whether a specific tool call with a specific argument is allowed in a specific moment of the session, and the egress gateway holds the production key the agent never sees.
Source
strands-agents/box on GitHub, by AWS Strands Agents.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.