Guide

Top Tools for Sandboxing the Pi Coding Agent

Pi is a real, open source coding agent that deliberately leaves access control to you. Its own documentation names the patterns; here is what each one actually restricts.

Quick Answer

Pi, the open source coding agent from earendil-works, ships with no sandbox and no permission popups on purpose. Its own README says plainly that Pi does not include a built-in permission system for restricting filesystem, process, network or credential access, and it names three patterns to add one: the Gondolin extension, which keeps Pi and its provider credentials on the host while routing tool calls and shell commands into a local Linux micro-VM; plain Docker, which containerizes the whole process for simple isolation; and OpenShell, which runs Pi inside a policy-controlled sandbox for finer-grained restriction. Beyond Pi's own options, developers also reach for macOS Seatbelt or Linux's bubblewrap and gVisor for a free local boundary, and cloud sandbox platforms such as e2b, Daytona or Modal when the code needs to run somewhere with no access to the host at all. None of these tools touches secrets, so pair whichever one you pick with a vault that hands Pi a credential without showing it the value.

Why Pi needs a tool you add yourself

Pi is a real, open source coding agent, MIT licensed, built by earendil-works as what its own documentation calls a minimal, extensible agent harness you can make your own. Minimal is the operative word: Pi's README states outright that it does not include a built-in permission system for restricting filesystem, process, network or credential access.

That is a deliberate design choice, not an oversight. Features other agents bake in by default, Pi leaves for you to add through extensions, which means the sandboxing tool you pick is part of setting Pi up, not an optional extra.

  • Pi has no filesystem, process, network or credential restrictions built in.
  • The project's own stance is that you build the boundary you need, through an extension or a wrapper.

What Pi's own documentation recommends

Pi's README has a section called Permissions and Containerization that names three concrete patterns instead of leaving the choice fully open. The Gondolin extension keeps Pi itself and its provider authentication on the host machine, while routing built-in tool calls and shell commands into a local Linux micro-VM, so the risky part of the work is isolated while Pi's own credentials never leave the host.

Plain Docker is the simpler option: the whole Pi process runs inside a container, which is easier to set up but gives you one boundary around everything rather than separating tool execution from the agent itself. OpenShell is the third pattern, running Pi inside what the documentation calls a policy-controlled sandbox, aimed at developers who want to define specific rules rather than accept a single all-or-nothing container.

  • Gondolin: Pi and its credentials stay on the host; tools and shell commands run in a local Linux micro-VM.
  • Plain Docker: the entire Pi process is containerized, simple but coarse.
  • OpenShell: a policy-controlled sandbox for defining your own rules.

The free, local option: your operating system's own sandbox

On a Mac, sandbox-exec applies a Seatbelt profile to any command, including Pi, at no cost and with no container to manage. Apple's own man page has marked sandbox-exec deprecated since OS X 10.12, but it still works on current macOS releases, and the sandboxes built into agents such as Claude Code and Codex are built on the same mechanism.

On Linux, bubblewrap and gVisor serve a similar role: bubblewrap is a lightweight namespace sandbox, while gVisor runs a container inside a user-space kernel for stronger isolation than a normal container gives you. Either one takes effort to tune, since a profile that blocks too much breaks your build tools and one that blocks too little protects nothing.

  • macOS: sandbox-exec with a Seatbelt profile, free, deprecated label but still functional.
  • Linux: bubblewrap for lightweight isolation, gVisor for a stronger boundary.
  • Expect to iterate on the policy; package managers and compilers touch many paths.

Cloud sandbox platforms for teams and products

When Pi's generated code needs to run somewhere with no access to your own machine at all, cloud sandbox platforms step in. E2B starts a hardware-isolated Firecracker microVM per session, with egress control over the network and real-time CPU, memory and disk metrics; its Hobby plan includes a one-time 100 dollar usage credit with 20 concurrent sandboxes and up to an hour of runtime each, while the Pro tier is 150 dollars a month for 100 concurrent sandboxes and 24-hour runtime.

Daytona positions itself as secure, elastic infrastructure for running AI-generated code, with sandboxes that run on isolated, customer-managed compute in your own cloud rather than shared compute, so there is no cross-tenant risk between different users' sessions. Modal offers both container-based sandboxes and full VM sandboxes it calls full computers for agents, with egress controls to lock down which domains an agent can reach, usage-based pricing by CPU core and memory, and 30 dollars a month of free compute to start.

  • e2b: Firecracker microVMs, egress control, Hobby plan from a one-time $100 credit.
  • Daytona: customer-managed compute in your own cloud, no shared compute between tenants.
  • Modal: container or full-VM sandboxes with domain-level egress controls and a $30/month free tier.

The part none of these cover: secrets

Every tool above limits what Pi can touch. None of them limits what a credential can do once Pi is holding it, which is a separate problem that needs a separate tool. HashiCorp Vault is the familiar name, though it is worth knowing it has shipped under the Business Source License, not an open source license, since version 1.15, a change kept in place since IBM completed its acquisition of HashiCorp on February 27, 2025. It still runs fully self-hosted.

Infisical is the clearly open source option: MIT licensed and fully self-hostable, with an Agent Vault feature aimed specifically at this case, where credentials are attached at the network boundary so, as its own description puts it, the agent makes authenticated calls without ever holding the credential.

  • A sandbox restricts what Pi can touch, not what a key does once Pi has used it.
  • HashiCorp Vault: self-hostable, Business Source License since v1.15, not open source.
  • Infisical: MIT licensed, self-hostable, with an Agent Vault mode built for agents specifically.

Where Forkbench fits for a Mac-based Pi setup

Pi is a command you run, so it starts and runs inside a Forkbench terminal the same way any other coding agent does. Forkbench can lock that Thread to its project folder using the macOS kernel sandbox, which is the same underlying mechanism as a hand-written Seatbelt profile but applied for you, and it can keep Pi's provider keys in its Vault so Pi uses a key by name without the value reaching the prompt or the transcript.

This is the local layer, not a replacement for the cloud platforms above when you genuinely do not trust the code Pi is about to run. Know the limits: the folder lock is opt-in and does not restrict the network, so a locked Pi session can still send out anything it is allowed to read, and an unpinned Vault key can still be read by the program it was handed to. Forkbench itself is Mac only today; Windows and Linux are in development, with no date.

  • Forkbench runs Pi in a locked terminal, folder-scoped by the macOS kernel sandbox.
  • Vault keeps Pi's provider keys out of the prompt and the transcript.
  • Folder lock does not restrict the network; an unpinned Vault key is still readable by the program using it.
  • Windows and Linux builds of Forkbench are in development, with no date.

Picking one for how you actually use Pi

Match the tool to how much you trust the code Pi is about to run. Everyday work you would review anyway fits a free local sandbox or Forkbench's folder lock. Code you are less sure about fits a container, Gondolin's micro-VM, or OpenShell's policy controls.

Code you would not run on your own machine at all is what the cloud platforms, e2b, Daytona or Modal, are for. Whichever layer you pick, add a vault for secrets separately; none of the sandboxing options above were built to solve that problem too.

  • Everyday work: a free local sandbox, or Forkbench's folder lock on a Mac.
  • Code you are not fully sure about: a container, Gondolin's micro-VM, or OpenShell.
  • Code you would not run locally at all: a cloud sandbox platform like e2b, Daytona or Modal.
  • Any tier: put provider keys in a vault, not in Pi's plain environment.

Related: How to sandbox AI coding agents on macOS safely, An e2b alternative for your own coding agents, Forkbench vs Docker Sandboxes, Download Forkbench

Frequently asked

  • Does Pi have a built-in sandbox?

    No. Pi's own README states it does not include a built-in permission system for restricting filesystem, process, network or credential access. You add a boundary yourself.

  • What is the Gondolin extension for Pi?

    It is one of Pi's own documented containerization patterns. It keeps Pi and its provider authentication on the host machine while routing tool calls and shell commands into a local Linux micro-VM.

  • Is Docker a safe sandbox for Pi?

    It is a reasonable boundary, not a perfect one. Docker Desktop has had flaws, such as CVE-2025-9074, where a container could reach the Docker Engine API without authentication; keep Docker updated and never mount the Docker socket into Pi's container.

  • What is the difference between a local sandbox and a cloud platform like e2b?

    A local sandbox, such as Seatbelt or a container, still shares your own machine's hardware and kernel. A cloud platform like e2b starts an isolated microVM per session, so the code never touches your machine at all, at the cost of latency and a bill.

  • Does a sandbox stop Pi from leaking an API key?

    No. A sandbox limits what Pi can touch, not what a credential can do once Pi is holding it. That needs a vault, such as Infisical's Agent Vault, kept separate from the sandbox.

  • Can Forkbench run Pi?

    Yes. Pi is a command, and Forkbench runs it in a terminal like any other coding agent, with the option to lock that Thread to its project folder and keep its keys in the Vault. Forkbench is Mac only today.

Keep reading