sandvault
« Back to VersTracker
Description:
Run AI agents isolated in a sandboxed macOS user account
Type: Formula  |  Tracked Since: Jan 19, 2026
Links: Homepage  |  GitHub  |  formulae.brew.sh
Stars: 21  |  Forks: 4  |  Language: Shell  |  Category: Security
Tags: security sandbox macos automation ai
Install: brew install sandvault
About:
Sandvault is a command-line tool that creates and manages isolated macOS user accounts to run AI agents and other processes in a secure sandbox. It leverages macOS's native security features to provide a lightweight, disposable environment, preventing agents from accessing your primary user data or system settings. This isolation is crucial for safely testing or executing untrusted AI code.
Key Features:
  • Creates isolated macOS user accounts for process sandboxing
  • Leverages native macOS security (sandbox-exec, opendirectoryd)
  • Provides a lightweight and disposable runtime environment
  • Command-line interface for automation and scripting
Use Cases:
  • Safely running and testing untrusted AI agents or scripts
  • Isolating development or build environments for security
Alternatives:
  • Docker – More complex, full containerization vs. Sandvault's lightweight macOS user account isolation
  • firejail – Linux-focused sandboxing tool, not natively available on macOS
Version History
Detected Version Rev Change Commit
Jan 19, 2026 8:59am 0 META b080a3a0