eugene1g/agent-safehouse
A macOS sandboxing tool for AI coding agents that uses deny-first policy profiles to restrict file and system access.

Not currently ranked — collecting fresh signals.
star history
Agent Safehouse restricts AI coding agents to only access files and integrations they explicitly need, using macOS’s sandbox-exec with composable deny-first policy profiles. It includes pre-built profiles for major coding agents and app-hosted agent workflows while keeping normal development usage practical. Developers install it via Homebrew or standalone script to add a hardening layer against unintended agent file access.
Frequently asked
- What is eugene1g/agent-safehouse?
- A macOS sandboxing tool for AI coding agents that uses deny-first policy profiles to restrict file and system access.
- Is agent-safehouse open source?
- Yes — eugene1g/agent-safehouse is open source, released under the Apache-2.0 license.
- What language is agent-safehouse written in?
- eugene1g/agent-safehouse is primarily written in Shell.
- How popular is agent-safehouse?
- eugene1g/agent-safehouse has 1.9k stars on GitHub.
- Where can I find agent-safehouse?
- eugene1g/agent-safehouse is on GitHub at https://github.com/eugene1g/agent-safehouse.