Sandboxes & Runtimes
10 agents tracked · Open-source-first, with limited public GitHub comparators · Ranked by trust score · Updated 2026-08-29 06:32 UTC
HVTracker independently evaluates 10 sandboxes & runtimes using daily signals from GitHub, package registries, and security databases. The category is open-source-first, with a limited set of public GitHub-hosted proprietary or source-available comparators when they are important ecosystem reference points. Each agent is scored on activity, adoption, transparency, safety, and identity. The top-ranked sandboxes & runtime is BoxLite with a trust score of 85.2/100 (Grade A). Other leading projects include E2B and Daytona.
| # | Agent | Trust | Stars | Language |
|---|---|---|---|---|
| 1 | BoxLite A Listed The micro-VM for AI agents — light enough to embed on your laptop, elastic enough to power an agentic cloud. | 85.2 | 2.3k | Rust |
| 2 | E2B B Listed Open-source, secure environment with real-world tools for enterprise-grade agents. | 78.4 | 13.6k | Python |
| 3 | Daytona B Listed Daytona is a Secure and Elastic Infrastructure for Running AI-Generated Code | 67.3 | 71.9k | TypeScript |
| 4 | Fence C Listed Lightweight, container-free sandbox for running commands with network and filesystem restrictions | 59.8 | 940 | Go |
| 5 | Container Use C Listed Development environments for coding agents. Enable multiple agents to work safely and independently with your preferred | 59.8 | 4.0k | Go |
| 6 | Agent Infra Sandbox C Listed All-in-One Sandbox for AI Agents that combines Browser, Shell, File, MCP and VSCode Server in a single Docker container. | 53.6 | 5.8k | Python |
| 7 | OpenSandbox D Listed Secure, Fast, and Extensible Sandbox runtime for AI agents. | 47.2 | 14.8k | Go |
| 8 | Cube Sandbox D Listed Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents. | 46.2 | 11.4k | Go |
| 9 | OpenShell D Listed OpenShell is the safe, private runtime for autonomous AI agents. | 42.1 | 8.4k | Rust |
| 10 | Zeroboot D Listed Sub-millisecond VM sandboxes for AI agents via copy-on-write forking | 34.8 | 2.4k | Rust |
Grade = trust band: A ≥ 80, B ≥ 65, C ≥ 50, D < 50 — methodology