Run inside a per-project microsandbox (libkrun microVM), booting in ~2 seconds.
--yolo, --dangerously-skip-permissions, etc- agent-vm instead provides the security.git remote -v; extend with --repo OWNER/NAME. gh pr create,
git push etc. are filtered at the proxy — off-list calls get a 403
before they reach GitHub.Although this is architected for security and every change is inspected for security, further security review is still needed. Currently a few major features are being worked on before intensive security review begins. If you are currently not sandboxing, then using this tool would be much more secure than that. Please try out the project and give feedback or star it and and come back to it in a month.
/dev/kvm (rw) and membership in the kvm group, or an
Apple Silicon Mac for the supported source-build workflow.cargo build
agent-vm setup # pulls the image this config boots from and verifies it boots
cd ~/your-project
agent-vm claude # a configured launch verb; see `agent-vm --help`
The launch verbs come from your tool configuration (two tiers, user-wins), so
agent-vm --help lists exactly the tools you have configured; agent-vm doctor
shows which config files were found and what they resolved to.
Full flag, subcommand, networking, and troubleshooting reference: USAGE.md.
Rust
89.4%
Shell
8.9%
Dockerfile
1.1%
Run inside a per-project microsandbox (libkrun microVM), booting in ~2 seconds.
--yolo, --dangerously-skip-permissions, etc- agent-vm instead provides the security.git remote -v; extend with --repo OWNER/NAME. gh pr create,
git push etc. are filtered at the proxy — off-list calls get a 403
before they reach GitHub.Although this is architected for security and every change is inspected for security, further security review is still needed. Currently a few major features are being worked on before intensive security review begins. If you are currently not sandboxing, then using this tool would be much more secure than that. Please try out the project and give feedback or star it and and come back to it in a month.
/dev/kvm (rw) and membership in the kvm group, or an
Apple Silicon Mac for the supported source-build workflow.cargo build
agent-vm setup # pulls the image this config boots from and verifies it boots
cd ~/your-project
agent-vm claude # a configured launch verb; see `agent-vm --help`
The launch verbs come from your tool configuration (two tiers, user-wins), so
agent-vm --help lists exactly the tools you have configured; agent-vm doctor
shows which config files were found and what they resolved to.
Full flag, subcommand, networking, and troubleshooting reference: USAGE.md.
Rust
89.4%
Shell
8.9%
Dockerfile
1.1%