Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Zerobox

Sandbox any command with file, network, credential controls

Details

External ID
47574871
Source
HN
Company
—
Product
Zerobox
Website domain
github.com
Launched
March 30, 2026
Cohort
—
Upvotes
141
Upvotes percentile
0.9360393603936039
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

I'm excited to introduce Zerobox, a cross-platform, single binary process sandboxing CLI written in Rust. It uses the sandboxing crates from the OpenAI Codex repo and adds additional functionalities like secret injection, SDK, etc.Watch the demo: https://www.youtube.com/watch?v=wZiPm9BOPCgZerobox follows the same sandboxing policy as Deno which is deny by default. The only operation that the command can run is reading files, all writes and network I/O are blocked by default. No VMs, no Docker, no remote servers.Want to block reads to /etc? zerobox --deny-read=/etc -- cat /etc/passwd cat: /etc/passwd: Operation not permitted How it works:Zerobox wraps any commands/programs, runs an MITM proxy and uses the native sandboxing solutions on each operating system (e.g BubbleWrap on Linux) to run the given process in a sandbox. The MITM proxy has two jobs: blocking network calls and injecting credentials at the network level.Think of it this way, I want to inject "Bearer OPENAI_API_KEY" but I don't want my sandboxed command to know about it, Zerobox does that by replacing "OPENAI_API_KEY" with a placeholder, then replaces it when the actual outbound network call is made, see this example: zerobox --secret OPENAI_API_KEY=$OPENAI_API_KEY --secret-host OPENAI_API_KEY=api.openai.com -- bun agent.ts Zerobox is different than other sandboxing solutions in the sense that it would allow you to easily sandbox any commands locally and it works the same on all platforms. I've been exploring different sandboxing solutions, including Firecracker VMs locally, and this is the closest I was able to get when it comes to sandboxing commands locally.The next thing I'm exploring is `zerobox claude` or `zerobox openclaw` which would wrap the entire agent and preload the correct policy profiles.I'd love to hear your feedback, especially if you are running AI Agents (e.g. OpenClaw), MCPs, AI Tools locally.

Enrichment

Theme
developer tools for AI agents
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
sandboxing tool for isolating command execution
Manually corrected
False

Could you build this?

Partial A CLI sandbox relies on complex low-level OS isolation primitives (seccomp, namespaces, eBPF, or landlock on Linux; sandbox-exec on macOS), which require deep systems security knowledge to get right without security bypasses.

What it would actually take: Implemented in Rust wrapping OS-specific isolation primitives (Landlock/seccomp on Linux, Apple sandbox profiles on macOS, or containers). The hard parts are cross-platform process isolation, transparent credential injection, fine-grained outbound network filtering (via eBPF or packet filtering), and robust path/inode canonicalization to prevent symlink escape vulnerabilities.

Discussion

20 comments analyzed.

Competitors mentioned: litterbox - container-based sandbox for development environments, Podman containers, Docker containers

Concerns raised: Filesystem sandboxing alone insufficient - outbound requests still allowed credential exfiltration, Network sandboxing difficult to implement without being annoying, Works inside unprivileged Docker requires specific seccomp profile and bubblewrap setup

Feature requests: Logging mode for all file operations a script attempts, Snapshotting capability - snapshot list/diff/restore commands, Auto-approve all access on first run and save to profile instead of prompting each access, Wildcard patterns in profiles to allow directory trees (e.g., ~/Documents/*), Documented standard way to use inside Docker containers

Competitors

Other products that read as similar to this one — 200 launches clear the similarity bar, closest 8 shown.

Attention rank: #19 of 201 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 134 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.