Skip to content
shlederPublic

About

Daemon-less OS security boundary & sandbox for AI coding agents (Codex, Claude Code, Cursor, Aider)

Topics

Resources

Security policy

Stars

45 stars

Watchers

0 watching

Forks

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Latest commit

 

History

1,872 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

██╗   ██╗███████╗████████╗████████╗ ██████╗ 
██║   ██║██╔════╝╚══██╔══╝╚══██╔══╝██╔═══██╗
██║   ██║█████╗     ██║      ██║   ██║   ██║
╚██╗ ██╔╝██╔══╝     ██║      ██║   ██║   ██║
 ╚████╔╝ ███████╗   ██║      ██║   ╚██████╔╝
  ╚═══╝  ╚══════╝   ╚═╝      ╚═╝    ╚═════╝ 

Vetto is an unprivileged kernel sandbox and security runtime for AI coding agents.

CI Release npm version crates.io Platforms License: Apache 2.0

Vetto Terminal Demo

Vetto enforces filesystem boundaries, network egress allowlists, and process tree containment directly between fork() and execve() with sub-millisecond cold start latency. It requires zero root privileges and runs without a background daemon.


Quickstart

Installation

Install via standalone shell script:

curl -fsSL https://raw.githubusercontent.com/shleder/vetto/main/install.sh | sh

Or via your preferred package manager:

# npm (cross-platform global binary)
npm install -g @shledery/vetto

# Homebrew (macOS & Linux)
brew install shleder/tap/vetto

# Cargo (crates.io)
cargo install vetto --locked
Manual binary download from GitHub Releases

Download pre-built archives from GitHub Releases:

  • Linux x86_64: vetto-x86_64-unknown-linux-gnu.tar.gz
  • Linux aarch64: vetto-aarch64-unknown-linux-gnu.tar.gz
  • macOS Apple Silicon: vetto-aarch64-apple-darwin.tar.gz
  • macOS Intel: vetto-x86_64-apple-darwin.tar.gz
  • Windows x86_64: vetto-x86_64-pc-windows-msvc.zip

Each archive includes SHA-256 checksums and minisign signatures (.minisig).


Usage

1. Transparent Agent Wrapping

Wrap all detected AI coding agents (claude, codex, cursor, opencode, aider) with a single command:

vetto enable --all

Run your agent as usual. Vetto transparently intercepts execution via lightweight shims in ~/.vetto/shims:

claude                # runs sandboxed under kernel LSM policies
codex                 # host credentials masked, network scoped to OpenAI API

To unwrap agents or restore direct execution:

vetto disable claude  # disable sandbox for claude
vetto disable --all   # remove all shims

2. Direct Sandbox Execution

Run arbitrary commands, test suites, or agent scripts inside a one-off sandbox:

vetto run -- claude
vetto -- npm test

3. Workspace Snapshot & Rollback

Vetto captures a copy-on-write snapshot before your agent runs:

vetto diff            # review modified, added, or removed files
vetto undo            # instantly revert all changes to pre-session state

4. Diagnostics & Verification

Inspect host kernel isolation features and verify security boundaries:

vetto doctor          # inspect Landlock ABI, namespaces, and cgroups v2
vetto verify          # run boundary verification suite against active policy
vetto audit --latest  # inspect cryptographic Merkle audit log of the last session

Isolation Model

Platform Filesystem Network Process Containment Startup Overhead
Linux (Tier 1) Landlock LSM (ABI 1–6) + CoW tmpfs CLONE_NEWNET namespaces + SNI relay cgroups v2 cgroup.kill + pidfd pinning < 4ms
macOS (Tier 2) Seatbelt (libsandbox.1.dylib) Loopback proxy + IP egress deny Child process group supervision < 8ms
Windows (Tier 3) LPAC AppContainer tokens Restricted network SIDs Job Objects (KILL_ON_JOB_CLOSE) < 15ms

Documentation


License

Licensed under the Apache License, Version 2.0.

About

Daemon-less OS security boundary & sandbox for AI coding agents (Codex, Claude Code, Cursor, Aider)

Topics

Resources

Security policy

Stars

45 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages