2026-10-11 17:09 UTC

SideKernel's developer claims its released Apache-2.0 microVM sandbox makes running Claude Code locally on macOS safely practical β€” current-directory sync, port auto-forwarding, clipboard and Claude-config passthrough, and a network kill switch β€” and developer adoption plus scrutiny of its self-acknowledged limits (no formal security review, unnotarized, Claude Code only) will decide whether usable microVM containment becomes a standard local-agent isolation pattern.

state: corroboratedheat: lowuncertainty: highconvergesscott: mediumagent-sandboxing coding-agents microvm agentic-securityMinoan Security

What is this?

SideKernel is an Apache-2.0, brew-installable microVM sandbox for running Claude Code on Apple-Silicon Macs, released on Show HN (2026-09-29) by Dimitrios Prasakis under the Minoan Security name β€” a Georgia Tech cybersecurity capstone published as a product. Its design bet is that strong containment wins adoption only by disappearing (two-way current-directory sync, port auto-forwarding, clipboard and host Claude-config passthrough, network kill switch), while its README concedes no formal security review, an unnotarized binary, and Claude-Code-only support; at day 5 it shows essentially no traction (1 point, 0 comments). The supplied snippets never mention SideKernel itself β€” its specifics rest on the case's first-party evidence, not independent web confirmation β€” but they do ground the landscape it entered: Docker Sandboxes has already popularized the same shape (per-sandbox microVM, workspace sync, agents run with --dangerously-skip-permissions under the doctrine 'the sandbox is the security boundary, not the permission system'), Anthropic ships native Seatbelt/bubblewrap sandboxing, a dozen-plus hobby microVM projects crowd the GitHub topic page (several already implementing host-side API-key handling and restricted egress β€” variants of SideKernel's differentiators), community scripts wrap Docker's sbx CLI, and on 2026-09-24 Docker extended the model to metered cloud sandboxes with a CNCF-bound Sandbox Kit spec. So SideKernel is a tractionless indie entrant arriving into a niche that is simultaneously proliferating at the hobby layer and consolidating under commercial incumbents.

Why it matters to Scott

Converges with the Give the Agent a Workshop thesis β€” an unrelated third party ships a microVM reversibility membrane whose explicit design bet is that containment only earns adoption by disappearing behind ergonomics, independently formalized further by the three-axis market frame. But SideKernel's host Claude-config passthrough is exactly the standing-credential crossing his capability-token/scope-separation doctrine forbids β€” and given radar evidence that Claude Code stores reusable OAuth tokens in that config, it is the case's sharpest unexamined risk β€” while the tractionless three-launch week gives him dated receipts on whether ergonomics alone actually dissolves sandbox-adoption friction.
ip:source.give-the-agent-a-workshop-ebookip:concept.sandboxed-executionip:concept.capability-tokensdev:technology.bubblewrapdev:technology.claude-coderadar:brig-microvm-agent-containmentradar:docker-cloud-sandboxes-releaseradar:claude-code-plaintext-oauth-tokensradar:concept.agent-sandboxingradar:concept.microvms
queries asked of Scott's wikis
  • workshop disposable microVM reversibility membrane
  • sandbox ergonomics adoption friction containment
  • agent credentials config crossing sandbox boundary
  • local coding agent harness macOS sandboxing
  • multi-harness agent support opencode codex claude
  • agent containment observability security tradeoff

Measured heat

now 0 pts/hpeak 6 pts/hcomments 0/hpeers p14momentum: steady3 platformsage 338h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

09-27 14:00⭐ origin echo-reconstructedOriginal work by the poster (HN user dimiprasakis = Dimitrios Prasakis), announced via Show HN. README: "SideKernel is a usable sandbox for
Dimitrios Prasakis (Minoan Security / Georgia Tech MSc Cybersecurity capstone) on github (echo) Β· attributed from hn.story.49891008
β€”
09-29 10:45first on hacker news Β· published Β· +44.8hShow HN: SideKernel – a usable MicroVM sandbox for AI coding agents on macOS
dimiprasakis
β€”
10-07 00:35first on r/ClaudeAI Β· published Β· +226.6hI let Claude Code work in a sandbox that can only reach the hosts I allow, and every connection it makes or tries gets logged
ilai456
β€”
09-29 10:45amplified on hacker newshn.story.49891008
dimiprasakis
peak 1 Β· 0 comments Β· 8% of case engagement
10-01 10:34amplified on hacker news πŸ‘‘hn.story.49920001
freakynit
peak 2 Β· 2 comments Β· 28% of case engagement
10-02 13:22amplified on hacker newshn.story.49933266
floydhead01
peak 1 Β· 0 comments Β· 8% of case engagement
10-03 03:57amplified on hacker newshn.story.49941250
jeswin
peak 4 Β· 0 comments Β· 28% of case engagement
10-07 00:35amplified on r/ClaudeAIreddit.post.1wzixdy
ilai456
peak 1 Β· 6 comments Β· 28% of case engagement
09-29 11:21our radar first saw it Β· +45.4hdiscovery anchor: hn.story.49891008β€”
pace: p51 vs 1032 stories at the 336h mark (now 338h old) β€” ahead of anthropic-pentagon-blacklist-ruling (1.1x), behind crowdstrike-safemind-security-agents (0.9x)

Evidence (6) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: SideKernel – a usable MicroVM sandbox for AI coding agents on macOS
Retrieved article excerpt

Open article Β· Retrieved 2026-09-29T11:27:21.351796+00:00

SideKernel: an easy-to-use microVM sandbox for AI coding agents on macOS

[**Paper**](https://sidekernel.com/sidekernel.pdf) Β Β·Β 
[**Site**](https://sidekernel.com) Β Β·Β 
[**Note from the developer**](https://sidekernel.com/essay/)

SideKernel is a usable sandbox for AI coding agents (e.g. Claude Code). "Usable" means it tries stays out of your way and to feel as if its not there. It is developed as a capstone project for Georgia Tech's MSc in Cybersecurity.

Beyond AI agents, SideKernel is useful for trying out software without installing it on your host (e.g. untrusted npm packages).

**Features:**

- The current folder is the sandbox: files sync both ways, and AI conversations persist across restarts.
- Ports opened in the sandbox are auto-forwarded to the host.
- Copy/paste of text and images works in and out of the sandbox (with most VMs it doesn't).
- The host's Claude config (skills, plugins) carries over to the sandbox.
- A network kill switch blocks all traffic when the sandbox holds sensitive data, while Claude keeps working.
- Log in to Claude once, on the host or in the sandbox, and both are authenticated.
- Non-mounted files are easy to bring in with `sk-drop <path>`, or by dragging and dropping them into Claude.
- The in-sandbox `save` command creates a personal layer that persists files, configs and installations across sandboxes.

Note

SideKernel is still in research preview and not yet ready for production use. Use it responsibly. Please read the [**Paper**](https://sidekernel.com/sidekernel.pdf) or the [**sidekernel.com**](https://sidekernel.com) to learn more.

## Install

Tested on M1 and M4 (macOS 26.2); other Apple silicon chips should work.

Install with `brew` (recommended)

```
brew tap minoansecurity/sidekernel https://github.com/minoansecurity/sidekernel && brew trust --formula minoansecurity/sidekernel/sidekernel
brew install sidekernel
```

Install directly from source:

```
rustup target add aarch64-unknown-linux-musl
git clone https://github.com/minoansecurity/sidekernel
cd sidekernel
make install
```

The first run builds the root filesystem so it might take a minute or two.

## Usage

**On the host** (from a project folder):

```
sk          # launch an ephemeral microVM, current directory mounted
sidekernel  # (alias: sk)
sclaude     # launch a sandbox and start Claude Code directly
```

Coming soon: `scodex`, `sgemini`, `sgrok`, and more.

**Inside the sandbox:**

```
sk-drop <host-path>   # copy a host file into the sandbox (requires approval on the host)
sk-net on/off         # block all outbound traffic
save                  # persist installed packages across sandboxes
fightsong             # Print's Georgia Tech's fight song on the terminal 🐝 (alias: ramblinwreck)
```

You can also **drag and drop** files directly into Claude Code.

**Limitations**

- The agent may read, edit or destroy anything in the mounted directory.
- A malicious agent can open ports to the host, exposing malicious services.
- Only Claude Code is integrated; other harnesses such as Codex are planned.
- SideKernel's security rests on its architecture, but the implementation has not had a formal security review.
- SideKernel is not yet notarized (it is self-signed).

The full list is in the [paper](https://sidekernel.com/sidekernel.pdf) and on the [website](https://sidekernel.com/).

## License

SideKernel is open-source software, licensed under the [Apache License, Version 2.0](https://github.com/minoansecurity/sidekernel/blob/main/LICENSE).
dimiprasakis10
🟧 echo.github ⭐Original work by the poster (HN user dimiprasakis = Dimitrios Prasakis), announced via Show HN. README: "SideKernel is a usable sandbox for Dimitrios Prasakis (Minoan Security / Georgia Tech MSc Cybersecurity capstone)β€”β€”
🟧 hnShow HN: Autobox – Make your agents sandbox themselvesfreakynit22
🟧 hnShow HN: Spens sandboxed, observable coding agentsfloydhead0110
🟧 hnNVX: An Ultra-Light Micro-VM Sandbox from Microsoftjeswin40
🟠 redditI let Claude Code work in a sandbox that can only reach the hosts I allow, and every connection it makes or tries gets logged
ClaudeAI
ilai45616

Interpretation history

Decision trace