Glossary

What is a coding agent sandbox?

An isolated environment, usually a container or virtual machine, where an agent can read, edit and run code without touching your own computer.

Updated October 1, 2026 · Other tools described as of October 1, 2026

Short answer. A sandbox limits what an agent's commands can reach: not your files, not your SSH keys, not your other projects. It doesn't protect whatever you put inside it, including the keys the run needs, and it only helps if getting the result back out is deliberate.

What it protects

  • Your computer and its files, SSH keys and browser sessions.
  • Your local checkout, since the agent works on its own copy.
  • Other projects, since each sandbox holds one task.

What it doesn't

A sandbox runs your repository's own commands, like install scripts and tests, next to the agent. A malicious dependency could read whatever the run was given, including its model key or a deploy token. Use scoped keys with spending limits, and pass credentials only to the runs that need them.

Kinds of sandbox

OS-level sandbox
BoundaryRules on one process, on your own machine
Trade-offLight and local; only as strong as the rules
Container
BoundaryShares the host's operating system kernel
Trade-offFast and light; a kernel bug can cross the boundary
Virtual machine
BoundaryIts own kernel on virtual hardware
Trade-offStronger isolation; slower to start
MicroVM
BoundaryA virtual machine trimmed to the minimum
Trade-offVM-level isolation with a faster start; more setup to operate

A git worktree isn't a sandbox. It keeps two branches' files apart on the same machine, but the agent still runs as you.

Network and credentials

Most sandboxes need the network to install dependencies, then don't need it for the task. Codex's cloud tasks work that way by default: a setup phase with network access, then an agent phase offline unless you allow it, with secrets only available during setup. Cursor's cloud agents let you restrict outbound domains.

How the main tools do it

As described on each tool's own docs, read on October 1, 2026.

  • Codex: a local sandbox with read-only, workspace-write and full-access modes; isolated OpenAI-managed containers in the cloud.
  • Cursor: cloud agents in isolated VMs with your repository, dependencies and secrets.
  • GitHub Copilot: an ephemeral environment powered by GitHub Actions, limited to one repository and one branch per task.
  • Conductor: git worktrees on your Mac, and managed cloud sandboxes on its Pro plan.

In Macaron

Macaron calls its sandboxes Computers: a Linux container per agent, in Docker on your Mac or on a cloud server you connect over SSH. Your Mac's folders, Docker socket and credentials aren't mounted into it. You can pause, stop and start it, and its files persist. To work on a Mac folder, Macaron makes a sandbox copy on the Computer, and Apply to Mac writes the changes back only if they apply cleanly. Servers the agent starts on port 3000, 5173 or 8080 show up as its screen.

Questions to ask of any sandbox

  • Which credentials are inside it during a run, and for how long?
  • Can it reach the internet, and does it need to?
  • How do changes get back to my code, and can I refuse them?
  • What happens to its files when the task ends?
  • Who else can get into it?

Questions

Is a container a sandbox?+

It can be, but containers share the host's kernel. A virtual machine is a stronger boundary for code you don't fully trust.

Is Docker on my Mac a real boundary?+

On a Mac, Docker runs Linux containers inside a virtual machine, so there's a VM between the container and macOS. What you mount into the container is the part to watch.

Do I still need to review changes from a sandbox?+

Yes. A sandbox stops the agent reaching your machine during the run; it doesn't make the change correct.

Can the agent still leak my code?+

Whatever it reads goes to the model provider, sandbox or not. A sandbox limits what else it can reach.

Does a sandbox slow the agent down?+

Starting one takes a moment, and dependencies have to be installed inside it. A persistent sandbox, like a Macaron Computer, keeps them between tasks.

Sources and dates

Facts about other products come only from these pages, on the dates shown; prices are as published that day. Macaron's own details are as shipped on October 1, 2026. Products change, so check their sites for the latest.

Keep reading