Compare
Brig compared
Brig gives a coding agent a machine of its own on your computer. The agent gets a kernel, your project and nothing else, a network rule you write, and its login from your keychain, in one command. This page scores Brig and every other sandbox people run agents in against the five things an unattended agent needs.
The tools fall into three kinds. A process sandbox filters what a process can ask the host kernel for: bubblewrap, Seatbelt, nono, and the sandboxes inside Claude Code, Codex and Cursor. A microVM gives the agent a kernel of its own on your machine: Brig, Docker Sandboxes, Apple container and microsandbox. A cloud sandbox runs the code on someone else's machine: E2B and Daytona.
What a coding agent needs #
| Need | Why |
|---|---|
| Its own kernel | The agent runs code it did not write, from packages, from the web and from the model. A kernel bug reachable from inside a process sandbox is a way out. A microVM puts a hypervisor in the path |
| The project, and nothing else | The agent needs your repository. It does not need your SSH keys, your cloud credentials, your browser profile or your other repositories |
| An egress rule by host, enforced outside | A sandbox with open internet can send anything it reads anywhere. The rule must name hosts, cover every protocol, and sit where the agent cannot reach it |
| Credentials by name, off the disk | The agent needs its login and perhaps one token. It must get those and no others, and the copy must not reach host disk |
| An agent in one command | The tool must know the agent's paths, its login and its settings, so a run needs no assembly |
Scorecard #
Each cell says what the tool does for that need. The pages linked in the first column give the detail and the sources.
| Tool | Own kernel | Project only | Egress by host | Credentials | One command |
|---|---|---|---|---|---|
| Brig | Yes. hvi on macOS, KVM on Linux | Yes. The project and the guest home | Yes. Hosts and ranges, at a gateway or in nftables outside the guest | Yes. A keychain store, delivered by name as a file. v0.5.0 adds brokerage, with a placeholder in the guest | Yes. Eight built-in profiles |
| bubblewrap | No. Namespaces on the host kernel | Yes, if you bind only the project | No. All or nothing | No. Environment variables | No. You write the bind list |
| Seatbelt | No. A policy in the host kernel | Yes, if the profile allows it. Most profiles read the whole disk | No. No rule by hostname | No | No. You write the profile |
| nono | No. Landlock and Seatbelt on the host kernel | Yes. Deny by default | Partial. A proxy on the host, or block all | Yes. A proxy adds the key to allowed requests | Yes. Profiles and client guides |
| Claude Code, Codex, Cursor | No. Seatbelt, bubblewrap and Landlock on the host kernel | No. Reads the whole disk, writes the project | Partial. A proxy on the host with a domain list | Partial. Claude Code masks at the proxy | Yes. Built in |
| Docker Sandboxes | Yes. A microVM per sandbox | Yes. The workspace | Partial. An HTTP proxy, with address rules for other TCP | Yes. A keychain store, with a sentinel the proxy swaps | Yes. Agent commands |
| Dev container | No. The Docker host's kernel | Yes, if you mount only the project | No. A firewall script inside the container | No. Variables, or the login inside | No. You write devcontainer.json |
| Apple container | Yes. A VM per container | Yes. The volumes you mount | No | No. Registry logins only | No. You bring an image |
| microsandbox | Yes. A libkrun microVM | Yes. The directory you mount | Yes. Hostname and address rules, checked on the host | Yes. A placeholder the host swaps on allowed hosts | No. A recipe per agent |
| E2B, Daytona | Yes, on their machines. Daytona's default is a container | Your project is uploaded | Yes. Lists by host and range | Partial. Stored with the provider | Yes, through an SDK |
What Brig gives you #
Brig is the one tool on the list that meets all five on your own machine, on macOS and on Linux, as open source.
- A kernel per sandbox. On macOS, hvi boots the guest on Hypervisor.framework and runs inside a Seatbelt profile of its own. On Linux, urunc boots it on Cloud Hypervisor. Architecture shows each layer.
- Your project, and nothing else from the host. The guest sees the project at
/work/<name>and its own home. Your keychain, SSH agent and other repositories are not there. Security lists what the agent can and cannot reach. - A network rule you write. A policy names the hosts and ranges the agent can reach. Brig enforces it at the gateway on macOS and in nftables on Linux, and refuses to boot where it cannot.
--network offlineleaves no route out. Networking has the format and a recording. - Logins from your keychain.
brig secret import claude-codecarries your login in once. Every run reads that store and delivers the credential as a file on a memory-backed mount. Secrets covers the store. - One command per agent.
brig run claude ~/code/demoopens Claude Code in its sandbox. Eight profiles ship: Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Grok, OpenCode and a plain Ubuntu shell.
microsandbox meets the first four. Its recipe installs the agent once per sandbox. Docker Sandboxes gives a microVM and a keychain store from a closed-source tool. nono is the nearest process sandbox, and runs on an Intel Mac and on a Linux host with no KVM.
Brig states its limits on the security model page. It needs Apple silicon and macOS 15 or newer, or a Linux host with KVM. A sandbox boots a kernel, so a cold start takes longer than a process sandbox. The agent holds its credential, where nono, Docker Sandboxes and Claude Code's mask keep the real value on the host. Brig v0.5.0 adds secret brokerage, and the guest then holds a placeholder. hvi, the VMM on macOS, is in process for an external security audit, and no formal third-party review is published at this time.
Other tools #
These do not have a page of their own. Each is a sandbox, and none is built for a coding agent on your machine.
| Tool | What it is | Why it is not on the scorecard |
|---|---|---|
| Firecracker, Kata Containers | MicroVM runtimes for Linux servers | Linux and KVM only. Firecracker needs root for the network setup, and Kata's shim and virtiofsd run as root. No agent, credential or egress layer. Brig's Linux path uses a cousin, Cloud Hypervisor, through urunc |
| gVisor | A user-space kernel for containers | Linux only. It narrows the host kernel's surface, and still runs on it. Gemini CLI can use it |
| microsandbox | A microVM sandbox for untrusted code, with host-side network rules and placeholder secrets | It is on the scorecard. Its Claude Code guide installs the agent with a recipe, once per sandbox, and its README calls it beta. The nearest tool to Brig in mechanism |
| Lima, OrbStack | Linux VMs on a Mac | General development VMs, with no agent, credential or egress layer. OrbStack runs one VM shared by every container and machine, and its documentation says an isolated machine is not a substitute for a full VM against malicious code |
| Firejail, nsjail | Linux namespace sandboxes | Shared kernel. Firejail is setuid root, and its man page says this is a risk |
| Landlock | A Linux kernel mechanism | A building block, not a tool. nono and Cursor use it |
Sources #
Each linked page lists its sources with the date they were read. The facts about Brig come from Security, Networking, Architecture and Runtimes on this site.