Developer previews · Linux + macOS VM

Give your agent only the access it needs.

Ouroboros Jail is a Linux sandbox for AI agents and command-line tools. Limit which files they can change, which services they can contact, and how long they can run. On Apple Silicon, try offline Linux commands in a disposable VM.

Install the developer preview

Detects your platform
curl --proto '=https' --tlsv1.2 -fsSL https://ouroboros.monocursive.com/install.sh | bash
export PATH="$HOME/.local/bin:$PATH"
# Linux: ouro-jail doctor --profile tool
# macOS: ouro-vm doctor

Linux: glibc 2.39+ and bubblewrap. Mac: Apple Silicon, macOS 27+, and 8 GiB free APFS storage. SHA-256 hashes are pinned in the installer. No compiler or sudo needed.

Install & host requirements ↗

New: Ouro VM for Mac

The signed, notarized 0.1.0-preview.1 release runs offline Linux ARM64 commands with tool and build profiles. It copies inputs into a disposable VM and returns files and receipts for review. Native Mac programs, Xcode and online agents are outside this preview.

Mac quickstart and preview limits

Security

Enforce permissions outside the agent.

The ouro-jail command uses bubblewrap and Linux kernel controls to restrict a process and its children. Your existing agent keeps its own models and workflow.

File access

Give the process a workspace and specific read-only or writable paths. Your home directory is not exposed by default. System runtime files remain available so programs can execute.

Network access

Local tools and builds run without a network. Agents connect through a proxy that checks destinations against your allowlist. You choose which services they can reach.

Runtime limits

Set a deadline for the command. Add memory, CPU, and process limits on hosts with delegated cgroup controls. If a required control is unavailable, the jail refuses the run.

A record of the run

A receipt records the policy that was applied, the result, and any missing evidence. Observation is on by default and logs a defined set of operations; it does not capture every action.

The grants still matter.

An agent can change files you make writable and send readable data to services you allow. Start with a small set of permissions and inspect the result. Containment relies on the host kernel; this is pre-release software with security review still ahead of release.

Understand the boundary

Use cases

Where the jail helps

Pick a profile for the job, then grant the paths and services that command needs.

agent profile

Let a coding agent work on a project

Make the checkout writable and allow the model endpoints it needs. Keep unrelated projects and credentials outside its file grants. Review the diff when it finishes.

tool profile

Run tests from an unfamiliar repository

Use a disposable checkout with no network access and a time limit. Grant installed dependencies as read-only paths when needed.

build profile

Build from read-only source

Give a build command read-only inputs, a writable output directory, and scratch space. Set a memory limit and keep the network closed.

Choose a profile

Performance

What does the sandbox cost?

On Linux, processes run on the host kernel. Setting up containment takes time, and observing operations adds work while the command runs. The Mac preview boots a VM for each attempt; measured startup was about 22 seconds.

In our recorded Linux benchmark, the highest p95 added startup time across the tested workloads was 131 ms with observation off.

Observation is on by default. In the file-heavy fixture shown here, it raised median total runtime from 375 ms to 1,167 ms. Expect the cost to depend on what your command does.

Recorded on 29 September 2026 on the Ubuntu reference host, using an earlier development build. These are synthetic workloads, not an agent speed estimate.

5,000 file-operation rounds
Median total runtime · plain session · 30 samples per mode
Execution modeTime
Direct, without the jail190 ms
Jailed, observation off375 ms
Jailed, observation on Default1,167 ms

The full benchmark contains 540 measured launches. All 60 observation-off no-op runs finished too quickly for the jail to confirm execution and returned exec_unconfirmed with exit code 1. Their startup timings are included; they are not successful run receipts.

Read the method, raw results, and limitations

Availability

Choose your host.

Signed developer packages are available for Linux x86_64 and ARM64. Read the Linux release notes and use ouro-jail doctor to check your host.

Apple Silicon Macs have a separate offline VM preview. Follow the Mac quickstart for ouro-vm. Native macOS execution remains research; this preview runs Linux inside a VM and does not require Endpoint Security approval.

On Linux, fourteen starter launch profiles are included. OpenCode has recorded live runs; other agent and version combinations still need testing.

When a command needs more access, learn can propose missing read and network permissions from an observed run. You review the proposal before applying it.

Run an existing agent

Planned work

What we’re working on next

Read the roadmap

Next

Broader host compatibility

Extend clean-machine installation and enforcement records beyond the reference Linux hosts.

Next

More tested agents

Run each agent and version against a current jail build, then publish the compatibility results and updated benchmarks.

Research

Native macOS execution

Resolve process cleanup when the supervising helper dies. Apple entitlement approval is also pending; approval alone will not make execution ready.

Shared run records and company-managed Linux workers are planned further out. There are no release dates for these yet.