File access
Give the process a workspace and specific read-only or writable paths. Your home directory is not exposed by default. System runtime files remain available so programs can execute.
Developer previews · Linux + macOS VM
Ouroboros Jail is a Linux sandbox for AI agents and command-line tools. Limit which files they can change, which services they can contact, and how long they can run. On Apple Silicon, try offline Linux commands in a disposable VM.
curl --proto '=https' --tlsv1.2 -fsSL https://ouroboros.monocursive.com/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"
# Linux: ouro-jail doctor --profile tool
# macOS: ouro-vm doctorLinux: glibc 2.39+ and bubblewrap. Mac: Apple Silicon, macOS 27+, and 8 GiB free APFS storage. SHA-256 hashes are pinned in the installer. No compiler or sudo needed.
Install & host requirements ↗The signed, notarized 0.1.0-preview.1 release runs offline Linux ARM64 commands with tool and build profiles. It copies inputs into a disposable VM and returns files and receipts for review. Native Mac programs, Xcode and online agents are outside this preview.
Security
The ouro-jail command uses bubblewrap and Linux kernel controls to restrict a process and its children. Your existing agent keeps its own models and workflow.
Give the process a workspace and specific read-only or writable paths. Your home directory is not exposed by default. System runtime files remain available so programs can execute.
Local tools and builds run without a network. Agents connect through a proxy that checks destinations against your allowlist. You choose which services they can reach.
Set a deadline for the command. Add memory, CPU, and process limits on hosts with delegated cgroup controls. If a required control is unavailable, the jail refuses the run.
A receipt records the policy that was applied, the result, and any missing evidence. Observation is on by default and logs a defined set of operations; it does not capture every action.
An agent can change files you make writable and send readable data to services you allow. Start with a small set of permissions and inspect the result. Containment relies on the host kernel; this is pre-release software with security review still ahead of release.
Understand the boundaryUse cases
Pick a profile for the job, then grant the paths and services that command needs.
agent profile
Make the checkout writable and allow the model endpoints it needs. Keep unrelated projects and credentials outside its file grants. Review the diff when it finishes.
tool profile
Use a disposable checkout with no network access and a time limit. Grant installed dependencies as read-only paths when needed.
build profile
Give a build command read-only inputs, a writable output directory, and scratch space. Set a memory limit and keep the network closed.
Performance
On Linux, processes run on the host kernel. Setting up containment takes time, and observing operations adds work while the command runs. The Mac preview boots a VM for each attempt; measured startup was about 22 seconds.
In our recorded Linux benchmark, the highest p95 added startup time across the tested workloads was 131 ms with observation off.
Observation is on by default. In the file-heavy fixture shown here, it raised median total runtime from 375 ms to 1,167 ms. Expect the cost to depend on what your command does.
Recorded on 29 September 2026 on the Ubuntu reference host, using an earlier development build. These are synthetic workloads, not an agent speed estimate.
| Execution mode | Time |
|---|---|
| Direct, without the jail | 190 ms |
| Jailed, observation off | 375 ms |
| Jailed, observation on Default | 1,167 ms |
The full benchmark contains 540 measured launches. All 60 observation-off no-op runs finished too quickly for the jail to confirm execution and returned exec_unconfirmed with exit code 1. Their startup timings are included; they are not successful run receipts.
Availability
Signed developer packages are available for Linux x86_64 and ARM64. Read the Linux release notes and use ouro-jail doctor to check your host.
Apple Silicon Macs have a separate offline VM preview. Follow the Mac quickstart for ouro-vm. Native macOS execution remains research; this preview runs Linux inside a VM and does not require Endpoint Security approval.
On Linux, fourteen starter launch profiles are included. OpenCode has recorded live runs; other agent and version combinations still need testing.
When a command needs more access, learn can propose missing read and network permissions from an observed run. You review the proposal before applying it.
Planned work
Next
Extend clean-machine installation and enforcement records beyond the reference Linux hosts.
Next
Run each agent and version against a current jail build, then publish the compatibility results and updated benchmarks.
Research
Resolve process cleanup when the supervising helper dies. Apple entitlement approval is also pending; approval alone will not make execution ready.
Shared run records and company-managed Linux workers are planned further out. There are no release dates for these yet.