minoansecurity/sidekernel

An easy-to-use, secure macOS sandbox for Claude and other AI coding agents

Swift

3

9 commits

updated Sep 29, 2026

See the code

See what people are saying

README

SideKernel: an easy-to-use microVM sandbox for AI coding agents on macOS

Paper  ·  Site  ·  Note from the developer

SideKernel is a usable sandbox for AI coding agents (e.g. Claude Code). "Usable" means it tries stays out of your way and to feel as if its not there. It is developed as a capstone project for Georgia Tech's MSc in Cybersecurity.

Beyond AI agents, SideKernel is useful for trying out software without installing it on your host (e.g. untrusted npm packages).

Features:
  • The current folder is the sandbox: files sync both ways, and AI conversations persist across restarts.
  • Ports opened in the sandbox are auto-forwarded to the host.
  • Copy/paste of text and images works in and out of the sandbox (with most VMs it doesn't).
  • The host's Claude config (skills, plugins) carries over to the sandbox.
  • A network kill switch blocks all traffic when the sandbox holds sensitive data, while Claude keeps working.
  • Log in to Claude once, on the host or in the sandbox, and both are authenticated.
  • Non-mounted files are easy to bring in with sk-drop <path>, or by dragging and dropping them into Claude.
  • The in-sandbox save command creates a personal layer that persists files, configs and installations across sandboxes.

[!NOTE] SideKernel is still in research preview and not yet ready for production use. Use it responsibly. Please read the Paper or the sidekernel.com to learn more.

Install

Tested on M1 and M4 (macOS 26.2); other Apple silicon chips should work.

Install with brew (recommended)

brew tap minoansecurity/sidekernel https://github.com/minoansecurity/sidekernel && brew trust --formula minoansecurity/sidekernel/sidekernel
brew install sidekernel

Install directly from source:

rustup target add aarch64-unknown-linux-musl
git clone https://github.com/minoansecurity/sidekernel
cd sidekernel
make install

The first run builds the root filesystem so it might take a minute or two.

Usage

On the host (from a project folder):

sk          # launch an ephemeral microVM, current directory mounted
sidekernel  # (alias: sk)
sclaude     # launch a sandbox and start Claude Code directly

Coming soon: scodex, sgemini, sgrok, and more.

Inside the sandbox:

sk-drop <host-path>   # copy a host file into the sandbox (requires approval on the host)
sk-net on/off         # block all outbound traffic
save                  # persist installed packages across sandboxes
fightsong             # Print's Georgia Tech's fight song on the terminal 🐝 (alias: ramblinwreck)

You can also drag and drop files directly into Claude Code.

Limitations
  • The agent may read, edit or destroy anything in the mounted directory.
  • A malicious agent can open ports to the host, exposing malicious services.
  • Only Claude Code is integrated; other harnesses such as Codex are planned.
  • SideKernel's security rests on its architecture, but the implementation has not had a formal security review.
  • SideKernel is not yet notarized (it is self-signed).

The full list is in the paper and on the website.

License

SideKernel is open-source software, licensed under the Apache License, Version 2.0.

minoansecurity/sidekernel

An easy-to-use, secure macOS sandbox for Claude and other AI coding agents

Swift

3

9 commits

updated Sep 29, 2026

See the code

See what people are saying

README

SideKernel: an easy-to-use microVM sandbox for AI coding agents on macOS

Paper  ·  Site  ·  Note from the developer

SideKernel is a usable sandbox for AI coding agents (e.g. Claude Code). "Usable" means it tries stays out of your way and to feel as if its not there. It is developed as a capstone project for Georgia Tech's MSc in Cybersecurity.

Beyond AI agents, SideKernel is useful for trying out software without installing it on your host (e.g. untrusted npm packages).

Features:
  • The current folder is the sandbox: files sync both ways, and AI conversations persist across restarts.
  • Ports opened in the sandbox are auto-forwarded to the host.
  • Copy/paste of text and images works in and out of the sandbox (with most VMs it doesn't).
  • The host's Claude config (skills, plugins) carries over to the sandbox.
  • A network kill switch blocks all traffic when the sandbox holds sensitive data, while Claude keeps working.
  • Log in to Claude once, on the host or in the sandbox, and both are authenticated.
  • Non-mounted files are easy to bring in with sk-drop <path>, or by dragging and dropping them into Claude.
  • The in-sandbox save command creates a personal layer that persists files, configs and installations across sandboxes.

[!NOTE] SideKernel is still in research preview and not yet ready for production use. Use it responsibly. Please read the Paper or the sidekernel.com to learn more.

Install

Tested on M1 and M4 (macOS 26.2); other Apple silicon chips should work.

Install with brew (recommended)

brew tap minoansecurity/sidekernel https://github.com/minoansecurity/sidekernel && brew trust --formula minoansecurity/sidekernel/sidekernel
brew install sidekernel

Install directly from source:

rustup target add aarch64-unknown-linux-musl
git clone https://github.com/minoansecurity/sidekernel
cd sidekernel
make install

The first run builds the root filesystem so it might take a minute or two.

Usage

On the host (from a project folder):

sk          # launch an ephemeral microVM, current directory mounted
sidekernel  # (alias: sk)
sclaude     # launch a sandbox and start Claude Code directly

Coming soon: scodex, sgemini, sgrok, and more.

Inside the sandbox:

sk-drop <host-path>   # copy a host file into the sandbox (requires approval on the host)
sk-net on/off         # block all outbound traffic
save                  # persist installed packages across sandboxes
fightsong             # Print's Georgia Tech's fight song on the terminal 🐝 (alias: ramblinwreck)

You can also drag and drop files directly into Claude Code.

Limitations
  • The agent may read, edit or destroy anything in the mounted directory.
  • A malicious agent can open ports to the host, exposing malicious services.
  • Only Claude Code is integrated; other harnesses such as Codex are planned.
  • SideKernel's security rests on its architecture, but the implementation has not had a formal security review.
  • SideKernel is not yet notarized (it is self-signed).

The full list is in the paper and on the website.

License

SideKernel is open-source software, licensed under the Apache License, Version 2.0.

Languages

Swift

61.3%

Rust

32.1%

Shell

4.9%