* [vm2 v3.11.7](https://github.com/patriksimek/vm2) – Sandbox for running untrusted code with controlled access to Node.js built-in modules and secure context isolation. * [Microsandbox v0.6.15](https://github.com/superradcompany/microsandbox) – Secure, local-first programmable sandboxes using hardware-isolated microVMs that boot in milliseconds for AI agents. * [Axern v0.5.0](https://github.com/cofy-x/axern) – Axern provides an agent sandbox and durable service platform that isolates untrusted code and runs trusted long-lived workloads with a shared resource and lifecycle model. * [sandboxed v0.3.12](https://github.com/tastyeffectco/sandboxd) – Self-hosted developer sandboxes providing live preview URLs, one-command install, agent-driven code generation, and on-demand sleep/wake. * [gVisor release-20260817.0](https://github.com/google/gvisor) – Application kernel providing strong isolation between applications and the host operating system. * [vArmor v0.10.4](https://github.com/bytedance/vArmor) – Cloud-native container sandbox using AppArmor, BPF LSM, and Seccomp to harden containers and reduce kernel attack surface. * [Fence v0.1.66](https://github.com/fencesandbox/fence) – Lightweight, container-free sandbox for running commands with network and filesystem restrictions. * [CubeSandbox v0.7.0-rc2](https://github.com/TencentCloud/CubeSandbox) – Hardware-isolated sandbox service for AI agents, built on RustVMM and KVM with fast startup, high concurrency, and E2B SDK compatibility. * [K8E v1.35.5-20260811+k8e...](https://github.com/xiaods/k8e) – Lightweight CNCF-conformant Kubernetes distribution optimized for rapid deployment, enterprise high-availability, and secure AI agent sandboxing.