On Oct 7 AWS released Strands Box v0.1.0, an open-source (Rust, Apache 2.0) sandbox for AI agents. It pairs OS-level isolation with the Dogwood policy language: shell, Python, outbound HTTP and MCP calls all pass through one default-deny policy engine with a shared event history, so rules can depend on earlier actions and elapsed time. A gateway injects credentials so the agent never sees the secrets. Preview supports macOS on Apple silicon only; Linux is in development.
Key Takeaways
- ✓Release: v0.1.0 shipped 2026-10-07 17:24 UTC, written in Rust, Apache 2.0 (GitHub)
- ✓Default deny: engine-checked operations need a matching permit, and forbid overrides it (Dogwood)
- ✓Temporal rule example: an agent may post Slack status updates at most 3 times per 10 minutes; git push timing and API spend caps work the same way (The Register)
- ✓Platforms: macOS 15+ on Apple silicon only for now; Linux in development, Windows on the radar, AgentCore / ECS / Kubernetes planned
- ✓Benchmarks: AWS has not published performance or security benchmark numbers
Key Decision Metrics at a Glance
Heavy Claude Code use: compare subscription limits and API bills
Compare 40 dev plans & simulate token costs vs $20/mo subscriptions
Project Links & Resources
Direct AccessIn-Depth Technical Analysis
Strands Box is AWS's open-source sandbox engine for AI agents (v0.1.0, Oct 7 2026, Rust, Apache 2.0). It splits control into two layers: box.toml holds direct file, program and network grants enforced by the OS, while policy.dw holds Dogwood rules evaluated by the embedded Dogwood Local Engine. Strands Shell, Monty for Python, an egress gateway and an MCP broker run in a trusted process outside the agent sandbox and send every operation they handle to that engine, which denies by default and lets forbid override permit. Because they share one event history, rules can depend on earlier actions and elapsed time, e.g. deny outbound HTTP after a sensitive file read, or allow Slack status posts at most three times per ten minutes. The gateway injects API credentials or SigV4 signatures so the agent never sees secrets, and decisions are logged as OTLP JSON. AWS has published no performance or security benchmarks. The preview runs on macOS 15+ on Apple silicon only; Linux is in development and AgentCore, ECS and Kubernetes deployment is planned.
Benchmark side-by-side against alternatives, or calculate monthly token cost vs subscription break-even.
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.