File access
Give the process a workspace and specific read-only or writable paths. Your home directory is not exposed by default. System runtime files remain available so programs can execute.
Pre-release · Linux x86_64
Ouroboros Jail is a Linux sandbox for AI agents and command-line tools. Limit which files they can change, which services they can contact, and how long they can run.
ouro-jail run --profile tool --workspace "$PWD" --limit wall=30s -- /usr/bin/trueThis grants a writable workspace, blocks network access, and sets a 30-second deadline.
Build & host requirements ↗Security
The ouro-jail command uses bubblewrap and Linux kernel controls to restrict a process and its children. Your existing agent keeps its own models and workflow.
Give the process a workspace and specific read-only or writable paths. Your home directory is not exposed by default. System runtime files remain available so programs can execute.
Local tools and builds run without a network. Agents connect through a proxy that checks destinations against your allowlist. You choose which services they can reach.
Set a deadline for the command. Add memory, CPU, and process limits on hosts with delegated cgroup controls. If a required control is unavailable, the jail refuses the run.
A receipt records the policy that was applied, the result, and any missing evidence. Observation is on by default and logs a defined set of operations; it does not capture every action.
An agent can change files you make writable and send readable data to services you allow. Start with a small set of permissions and inspect the result. Containment relies on the host kernel; this is pre-release software with security review still ahead of release.
Understand the boundaryUse cases
Pick a profile for the job, then grant the paths and services that command needs.
agent profile
Make the checkout writable and allow the model endpoints it needs. Keep unrelated projects and credentials outside its file grants. Review the diff when it finishes.
tool profile
Use a disposable checkout with no network access and a time limit. Grant installed dependencies as read-only paths when needed.
build profile
Give a build command read-only inputs, a writable output directory, and scratch space. Set a memory limit and keep the network closed.
Performance
Processes run on the host kernel. Setting up containment takes time, and observing operations adds work while the command runs.
In our recorded Linux benchmark, the highest p95 added startup time across the tested workloads was 131 ms with observation off.
Observation is on by default. In the file-heavy fixture shown here, it raised median total runtime from 375 ms to 1,167 ms. Expect the cost to depend on what your command does.
Recorded on 29 September 2026 on the Ubuntu reference host, using an earlier development build. These are synthetic workloads, not an agent speed estimate.
| Execution mode | Time |
|---|---|
| Direct, without the jail | 190 ms |
| Jailed, observation off | 375 ms |
| Jailed, observation on Default | 1,167 ms |
The full benchmark contains 540 measured launches. All 60 observation-off no-op runs finished too quickly for the jail to confirm execution and returned exec_unconfirmed with exit code 1. Their startup timings are included; they are not successful run receipts.
Availability
Execution is validated on Linux x86_64. Build from source and use doctor to check your host. macOS builds can inspect policy, but currently refuse sandboxed execution.
Fourteen starter launch profiles are included. OpenCode has recorded live runs; other agent and version combinations still need testing.
When a command needs more access, learn can propose missing read and network permissions from an observed run. You review the proposal before applying it.
Planned work
Next
Finish the clean-VM onboarding test and configure signed public releases. For now, installation is from source.
Next
Run each agent and version against a current jail build, then publish the compatibility results and updated benchmarks.
Research
Resolve process cleanup when the supervising helper dies. Apple entitlement approval is also pending; approval alone will not make execution ready.
Shared run records and company-managed Linux workers are planned further out. There are no release dates for these yet.