multikernel/sandlock
Lightweight Linux process sandbox using Landlock and seccomp, designed to confine untrusted AI agent code.

Sandlock is a Rust-based sandbox for Linux that confines untrusted processes using Landlock for filesystem and network isolation, seccomp-bpf for syscall filtering, and seccomp user notification for resource limits and /proc virtualization. It runs without root, containers, or VMs, and includes a COW filesystem, HTTP-level ACLs, and SDKs for Python and Go. The project positions itself as protection against prompt injection for AI agents executing untrusted code.
Frequently asked
- What is multikernel/sandlock?
- Lightweight Linux process sandbox using Landlock and seccomp, designed to confine untrusted AI agent code.
- Is sandlock open source?
- Yes — multikernel/sandlock is open source, released under the Apache-2.0 license.
- What language is sandlock written in?
- multikernel/sandlock is primarily written in Rust.
- How popular is sandlock?
- multikernel/sandlock has 524 stars on GitHub.
- Where can I find sandlock?
- multikernel/sandlock is on GitHub at https://github.com/multikernel/sandlock.