Brood Box — AI skill for Claude Code
10+ Run AI coding agents (Claude Code, Codex, OpenCode) inside hardware-isolated microVMs with snapshot isolation, egress control, and MCP authorization.
How to install Brood Box
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open stacklok/brood-box and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Brood Box does
**Warning** > This project is **EXPERIMENTAL**. APIs, CLI flags, config format, and behavior may change without notice between releases. Use at your own risk and please report issues.
Alternatives in AI
- Pi Agent VS OpenCode — Customization & Control Comparison — Pi v0.52+ vs OpenCode v1.1+ (Feb 2026) Thesis: Pi and OpenCode are both MIT-licensed, open-source, model-agnos 526 ★
- Claudexor — Multi-harness control plane for Claude Code, Codex, Cursor, and OpenCode: quota-aware rotation across multiple 425 ★
- AI Surface — Find and govern AI attack surfaces in application code, at PR time and inside your AI coding tool (MCP server 131 ★
README
Brood Box
**Warning** This project is **EXPERIMENTAL**. APIs, CLI flags, config format, and behavior may change without notice between releases. Use at your own risk and please report issues.
Run coding agents in hardware-isolated microVMs. Review every change before it touches your workspace.
[](LICENSE) [](https://github.com/stacklok/brood-box/actions/workflows/ci.yaml) [](https://goreportcard.com/report/github.com/stacklok/brood-box) [](https://www.repostatus.org/#experimental)
Table of Contents
- Why?
- Features
- Quick Start
- Usage
- Configuration
- Egress Firewall
- Supported Agents
- How It Works
- Security Model
- Documentation
- Building from Source
- Contributing
- License
Why?
Coding agents are powerful, but they need access to your workspace, your API keys, and the ability to run arbitrary code. That's a lot of trust to hand over.
Containers help, but they share the host kernel. One escape and you're done.
Enter **Brood Box**. It boots a lightweight microVM (via [libkrun](https://github.com/containers/libkrun) and KVM), mounts a copy-on-write snapshot of your workspace, forwards only the secrets you specify, and lets you review every file change before it lands. Hardware isolation with the feel of a local terminal.
bbox claude-code
And that's it. You get a full interactive session with Claude Code running inside a VM. When the agent exits, you review the diff and accept or reject each file.
Features
- Hardware-isolated microVMs -- KVM (Linux) and Hypervisor.framework (macOS) backed VMs via libkrun, not just containers
- Workspace snapshot & review -- COW snapshot so the agent never touches your real files; interactive per-file review with unified diffs when it's done
...
Related Skills
Dev Sandbox
Run untrusted code and AI agents in isolated Podman containers with krun microVMs. Network control, SSH, Privo
Agentacl
Access control and sandboxing for AI coding agents on macOS. Stop Claude Code, Codex, Gemini CLI, Copilot CLI
Ecorp
Your 24/7 software factory with all of your human and agent team mates in one digital office. An entire AI com
Devcontainer Airlock
Secure, layered devcontainers for AI coding agents: the agents work in a workbench with no GitHub token and no
Herdeck
Control panel for AI coding agents running under herdr — on a hardware Stream Deck (Ulanzi D200 or Elgato), a
AgentHydra
Every local AI coding session in one tab: Claude Code, Codex and OpenCode in a single list, with a queue you c
Related Agents
Developer Overview
code-container (container) creates isolated Docker environments for AI coding harnesses (Claude Code, OpenCode
Opencode
Coding subagent that runs inside opencode, on any provider and model opencode supports (OpenAI, Google, Moonsh
5dive
5dive exists for people who want a fleet of coding agents working unattended on hardware they control, without