██╗ ██╗███████╗████████╗████████╗ ██████╗ ██║ ██║██╔════╝╚══██╔══╝╚══██╔══╝██╔═══██╗ ██║ ██║█████╗ ██║ ██║ ██║ ██║ ╚██╗ ██╔╝██╔══╝ ██║ ██║ ██║ ██║ ╚████╔╝ ███████╗ ██║ ██║ ╚██████╔╝ ╚═══╝ ╚══════╝ ╚═╝ ╚═╝ ╚═════╝
Vetto is an unprivileged kernel sandbox and security runtime for AI coding agents.
Vetto enforces filesystem boundaries, network egress allowlists, and process tree containment directly between fork() and execve() with sub-millisecond cold start latency. It requires zero root privileges and runs without a background daemon.
Install via standalone shell script:
curl -fsSL https://raw.githubusercontent.com/shleder/vetto/main/install.sh | shOr via your preferred package manager:
# npm (cross-platform global binary)
npm install -g @shledery/vetto
# Homebrew (macOS & Linux)
brew install shleder/tap/vetto
# Cargo (crates.io)
cargo install vetto --lockedManual binary download from GitHub Releases
Download pre-built archives from GitHub Releases:
- Linux x86_64:
vetto-x86_64-unknown-linux-gnu.tar.gz - Linux aarch64:
vetto-aarch64-unknown-linux-gnu.tar.gz - macOS Apple Silicon:
vetto-aarch64-apple-darwin.tar.gz - macOS Intel:
vetto-x86_64-apple-darwin.tar.gz - Windows x86_64:
vetto-x86_64-pc-windows-msvc.zip
Each archive includes SHA-256 checksums and minisign signatures (.minisig).
Wrap all detected AI coding agents (claude, codex, cursor, opencode, aider) with a single command:
vetto enable --allRun your agent as usual. Vetto transparently intercepts execution via lightweight shims in ~/.vetto/shims:
claude # runs sandboxed under kernel LSM policies
codex # host credentials masked, network scoped to OpenAI APITo unwrap agents or restore direct execution:
vetto disable claude # disable sandbox for claude
vetto disable --all # remove all shimsRun arbitrary commands, test suites, or agent scripts inside a one-off sandbox:
vetto run -- claude
vetto -- npm testVetto captures a copy-on-write snapshot before your agent runs:
vetto diff # review modified, added, or removed files
vetto undo # instantly revert all changes to pre-session stateInspect host kernel isolation features and verify security boundaries:
vetto doctor # inspect Landlock ABI, namespaces, and cgroups v2
vetto verify # run boundary verification suite against active policy
vetto audit --latest # inspect cryptographic Merkle audit log of the last session| Platform | Filesystem | Network | Process Containment | Startup Overhead |
|---|---|---|---|---|
| Linux (Tier 1) | Landlock LSM (ABI 1–6) + CoW tmpfs | CLONE_NEWNET namespaces + SNI relay |
cgroups v2 cgroup.kill + pidfd pinning |
< 4ms |
| macOS (Tier 2) | Seatbelt (libsandbox.1.dylib) |
Loopback proxy + IP egress deny | Child process group supervision | < 8ms |
| Windows (Tier 3) | LPAC AppContainer tokens | Restricted network SIDs | Job Objects (KILL_ON_JOB_CLOSE) |
< 15ms |
- Platform Backends & Isolation Specs
- Agent Compatibility Registry (32+ agents)
- SWE-bench vs Docker Runtime Benchmark
- GitHub Actions CI/CD Integration
- Threat Model & Boundary Architecture
- Exit Codes & Failure Modes
- Security Policy
Licensed under the Apache License, Version 2.0.
