← all repositories

earendil-works/gondolin

A TypeScript-based Linux micro-VM sandbox for safely running AI agent-generated code with programmable network and filesystem policy controls.

1.4k stars TypeScript AgentsCoding Assistants
gondolin
Velocity · 7d
+11
★ / day
Trend
steady
star history

Gondolin provides isolated execution environments for AI agents by running their generated code inside local Linux micro-VMs (QEMU or krun backend). The host-side policy layer controls network access and filesystem permissions, with secrets injection limited to allowed destinations only. Developers can customize policies via JavaScript and manage sessions, snapshots, and resume states through a CLI.

heatdrop uses Google Analytics to see which pages get read — nothing else. Your call. How we handle data.