Pre-release · Linux x86_64

Give your agent only the access it needs.

Ouroboros Jail is a Linux sandbox for AI agents and command-line tools. Limit which files they can change, which services they can contact, and how long they can run.

Start with a small command

After building from source
ouro-jail run --profile tool --workspace "$PWD" --limit wall=30s -- /usr/bin/true

This grants a writable workspace, blocks network access, and sets a 30-second deadline.

Build & host requirements ↗

Security

Enforce permissions outside the agent.

The ouro-jail command uses bubblewrap and Linux kernel controls to restrict a process and its children. Your existing agent keeps its own models and workflow.

File access

Give the process a workspace and specific read-only or writable paths. Your home directory is not exposed by default. System runtime files remain available so programs can execute.

Network access

Local tools and builds run without a network. Agents connect through a proxy that checks destinations against your allowlist. You choose which services they can reach.

Runtime limits

Set a deadline for the command. Add memory, CPU, and process limits on hosts with delegated cgroup controls. If a required control is unavailable, the jail refuses the run.

A record of the run

A receipt records the policy that was applied, the result, and any missing evidence. Observation is on by default and logs a defined set of operations; it does not capture every action.

The grants still matter.

An agent can change files you make writable and send readable data to services you allow. Start with a small set of permissions and inspect the result. Containment relies on the host kernel; this is pre-release software with security review still ahead of release.

Understand the boundary

Use cases

Where the jail helps

Pick a profile for the job, then grant the paths and services that command needs.

agent profile

Let a coding agent work on a project

Make the checkout writable and allow the model endpoints it needs. Keep unrelated projects and credentials outside its file grants. Review the diff when it finishes.

tool profile

Run tests from an unfamiliar repository

Use a disposable checkout with no network access and a time limit. Grant installed dependencies as read-only paths when needed.

build profile

Build from read-only source

Give a build command read-only inputs, a writable output directory, and scratch space. Set a memory limit and keep the network closed.

Choose a profile

Performance

What does the sandbox cost?

Processes run on the host kernel. Setting up containment takes time, and observing operations adds work while the command runs.

In our recorded Linux benchmark, the highest p95 added startup time across the tested workloads was 131 ms with observation off.

Observation is on by default. In the file-heavy fixture shown here, it raised median total runtime from 375 ms to 1,167 ms. Expect the cost to depend on what your command does.

Recorded on 29 September 2026 on the Ubuntu reference host, using an earlier development build. These are synthetic workloads, not an agent speed estimate.

5,000 file-operation rounds
Median total runtime · plain session · 30 samples per mode
Execution modeTime
Direct, without the jail190 ms
Jailed, observation off375 ms
Jailed, observation on Default1,167 ms

The full benchmark contains 540 measured launches. All 60 observation-off no-op runs finished too quickly for the jail to confirm execution and returned exec_unconfirmed with exit code 1. Their startup timings are included; they are not successful run receipts.

Read the method, raw results, and limitations

Availability

Start on Linux.

Execution is validated on Linux x86_64. Build from source and use doctor to check your host. macOS builds can inspect policy, but currently refuse sandboxed execution.

Fourteen starter launch profiles are included. OpenCode has recorded live runs; other agent and version combinations still need testing.

When a command needs more access, learn can propose missing read and network permissions from an observed run. You review the proposal before applying it.

Run an existing agent

Planned work

What we’re working on next

Read the roadmap

Next

Simpler installation

Finish the clean-VM onboarding test and configure signed public releases. For now, installation is from source.

Next

More tested agents

Run each agent and version against a current jail build, then publish the compatibility results and updated benchmarks.

Research

Native macOS execution

Resolve process cleanup when the supervising helper dies. Apple entitlement approval is also pending; approval alone will not make execution ready.

Shared run records and company-managed Linux workers are planned further out. There are no release dates for these yet.