Repo of the Day
eugene1g/agent-safehouse
Published: Oct 11, 2026
Open repository ↗Sandbox your local AI agents so they can read/write only what they need
Summary
Agent Safehouse is a macOS shell tool that wraps sandbox-exec to restrict local LLM coding agents to only the files and integrations they need. It ships with composable policy profiles for major agents (claude, codex, amp) and uses a deny-first model, so by default an agent reaches only a narrow set of paths. The project describes itself as a hardening layer, not a guaranteed security boundary.
What it is useful for
The tool helps engineers run coding agents on macOS without giving them blanket access to your home directory, SSH keys, or unrelated projects. The default policy denies all access with a small set of home exceptions (XDG-style config and cache lookups, plus a few explicit home-scoped files) and explicit grants for the active workdir. The README notes that stat "$HOME" can succeed while ls "$HOME" and cat ~/secret.txt still fail unless a more specific rule grants that path.
Other practical uses documented in the README:
- Standardizing least-privilege sandboxing across a team. Shared profiles live in the repo; per-machine exceptions live in a local appended profile.
- Locking down sensitive files inside a writable workdir, e.g. denying reads and writes on
<workdir>/.envwhile the rest of the project remains usable. - Inspecting Git worktrees safely. When the workdir is a worktree root, Safehouse grants the shared Git metadata it needs and makes other linked worktrees readable for cross-tree inspection.
How engineers can use it
Safehouse is macOS-only. The README lists Linux alternatives including vetto, bubblewrap, firejail, nono.sh, sandlock, and isolated-agent. On macOS, install via Homebrew:
brew install eugene1g/safehouse/agent-safehouse
Or download the standalone script:
mkdir -p ~/.local/bin
curl -fsSL https://github.com/eugene1g/agent-safehouse/releases/latest/download/safehouse.sh \
-o ~/.local/bin/safehouse
chmod +x ~/.local/bin/safehouse
Then add a shell wrapper so shared folders are allowed once and per-machine exceptions live in a local profile:
export SAFEHOUSE_APPEND_PROFILE="$HOME/.config/agent-safehouse/local-overrides.sb"
safe() {
safehouse \
--add-dirs-ro="$HOME/server" \
--append-profile="$SAFEHOUSE_APPEND_PROFILE" \
"$@"
}
safe-claude() { safe claude --dangerously-skip-permissions "$@" }
A sample machine-local profile from the README denies access to the project's .env while allowing reads from a host-specific mount:
(allow file-read*
(home-literal "/.gitignore_global")
(subpath "/Volumes/Shared/Engineering")
)
(deny file-read* file-write* (workdir-literal "/.env"))
Documented limitations: built-in path resolution only covers read grants (writable and metadata-only built-in rules are not auto-expanded); the worktree snapshot does not refresh for already-running processes; and CI workflows run on macOS only, so behavior on other platforms is not covered in the repo. For full setup, policy options, and architecture, the README points to the VitePress docs at agent-safehouse.dev/docs and a policy builder at agent-safehouse.dev/policy-builder.