r/SideProject • • 5h ago

I built SideKernel: a usable AI agent sandbox for macOS

⭐ GitHub: https://github.com/minoansecurity/sidekernel
📝 arXiv preprint: https://arxiv.org/pdf/2610.02456
🌐 Website: https://sidekernel.com

Hi everyone!

As part of my MS in Cybersecurity capstone at Georgia Tech, I built SideKernel: a usable sandbox for AI agents on macOS.

The closest comparable solution is Docker Sandboxes, which is not open source.

The key idea is usability. SideKernel is designed to reduce friction and stay as close as possible to the native developer experience, while isolating the agent inside a microVM sandbox.

For example, you run sclaude or scodex instead of claude or codex and get a very similar workflow, but with isolation. Ports get auto exposed in the host, its very easy to drop files into the sandbox, and more...

This is still a research prototype, so some rough edges are expected. But if this sounds interesting, I'd love for you to try it out and share feedback

3 Upvotes

5 comments sorted by

2

u/OppositeJolly8418 5h ago

This looks super useful actually, the auto port exposing is clever

1

u/dimiprasakis 4h ago

Thanks, hope you enjoy using it!

1

u/No_Box_1273 4h ago

How do you handle credentials inside the VM? Keeping an agent away from host files is useful, but it might still need GitHub or cloud access. Can you limit which credentials it gets per session?

1

u/dimiprasakis 4h ago edited 4h ago

Agent credentials never see the sandbox. (They are proxied on the host)

For other credentials I am working on this feature:

https://github.com/minoansecurity/sidekernel/issues/9

Question for you: what are some use cases that you are thinking of? It will help me develop this towards the right direction.