SideKernel's developer claims its released Apache-2.0 microVM sandbox makes running Claude Code locally on macOS safely practical β current-directory sync, port auto-forwarding, clipboard and Claude-config passthrough, and a network kill switch β and developer adoption plus scrutiny of its self-acknowledged limits (no formal security review, unnotarized, Claude Code only) will decide whether usable microVM containment becomes a standard local-agent isolation pattern.
state: corroboratedheat: lowuncertainty: highconvergesscott: mediumagent-sandboxing coding-agents microvm agentic-securityMinoan Security
What is this?
SideKernel is an Apache-2.0, brew-installable microVM sandbox for running Claude Code on Apple-Silicon Macs, released on Show HN (2026-09-29) by Dimitrios Prasakis under the Minoan Security name β a Georgia Tech cybersecurity capstone published as a product. Its design bet is that strong containment wins adoption only by disappearing (two-way current-directory sync, port auto-forwarding, clipboard and host Claude-config passthrough, network kill switch), while its README concedes no formal security review, an unnotarized binary, and Claude-Code-only support; at day 5 it shows essentially no traction (1 point, 0 comments). The supplied snippets never mention SideKernel itself β its specifics rest on the case's first-party evidence, not independent web confirmation β but they do ground the landscape it entered: Docker Sandboxes has already popularized the same shape (per-sandbox microVM, workspace sync, agents run with --dangerously-skip-permissions under the doctrine 'the sandbox is the security boundary, not the permission system'), Anthropic ships native Seatbelt/bubblewrap sandboxing, a dozen-plus hobby microVM projects crowd the GitHub topic page (several already implementing host-side API-key handling and restricted egress β variants of SideKernel's differentiators), community scripts wrap Docker's sbx CLI, and on 2026-09-24 Docker extended the model to metered cloud sandboxes with a CNCF-bound Sandbox Kit spec. So SideKernel is a tractionless indie entrant arriving into a niche that is simultaneously proliferating at the hobby layer and consolidating under commercial incumbents.
Why it matters to Scott
Converges with the Give the Agent a Workshop thesis β an unrelated third party ships a microVM reversibility membrane whose explicit design bet is that containment only earns adoption by disappearing behind ergonomics, independently formalized further by the three-axis market frame. But SideKernel's host Claude-config passthrough is exactly the standing-credential crossing his capability-token/scope-separation doctrine forbids β and given radar evidence that Claude Code stores reusable OAuth tokens in that config, it is the case's sharpest unexamined risk β while the tractionless three-launch week gives him dated receipts on whether ergonomics alone actually dissolves sandbox-adoption friction.
ip:source.give-the-agent-a-workshop-ebookip:concept.sandboxed-executionip:concept.capability-tokensdev:technology.bubblewrapdev:technology.claude-coderadar:brig-microvm-agent-containmentradar:docker-cloud-sandboxes-releaseradar:claude-code-plaintext-oauth-tokensradar:concept.agent-sandboxingradar:concept.microvms
queries asked of Scott's wikis
- workshop disposable microVM reversibility membrane
- sandbox ergonomics adoption friction containment
- agent credentials config crossing sandbox boundary
- local coding agent harness macOS sandboxing
- multi-harness agent support opencode codex claude
- agent containment observability security tradeoff
Measured heat
now 0 pts/hpeak 6 pts/hcomments 0/hpeers p14momentum: steady3 platformsage 338h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion
How the heat travelled
pace: p51 vs 1032 stories at the 336h mark (now 338h old) β ahead of anthropic-pentagon-blacklist-ruling (1.1x), behind crowdstrike-safemind-security-agents (0.9x)
Evidence (6) β β canonical anchor
| source | object | author | score | comments |
| π§ hn | Show HN: SideKernel β a usable MicroVM sandbox for AI coding agents on macOSRetrieved article excerptOpen article Β· Retrieved 2026-09-29T11:27:21.351796+00:00 SideKernel: an easy-to-use microVM sandbox for AI coding agents on macOS
[**Paper**](https://sidekernel.com/sidekernel.pdf) Β Β·Β
[**Site**](https://sidekernel.com) Β Β·Β
[**Note from the developer**](https://sidekernel.com/essay/)
SideKernel is a usable sandbox for AI coding agents (e.g. Claude Code). "Usable" means it tries stays out of your way and to feel as if its not there. It is developed as a capstone project for Georgia Tech's MSc in Cybersecurity.
Beyond AI agents, SideKernel is useful for trying out software without installing it on your host (e.g. untrusted npm packages).
**Features:**
- The current folder is the sandbox: files sync both ways, and AI conversations persist across restarts.
- Ports opened in the sandbox are auto-forwarded to the host.
- Copy/paste of text and images works in and out of the sandbox (with most VMs it doesn't).
- The host's Claude config (skills, plugins) carries over to the sandbox.
- A network kill switch blocks all traffic when the sandbox holds sensitive data, while Claude keeps working.
- Log in to Claude once, on the host or in the sandbox, and both are authenticated.
- Non-mounted files are easy to bring in with `sk-drop <path>`, or by dragging and dropping them into Claude.
- The in-sandbox `save` command creates a personal layer that persists files, configs and installations across sandboxes.
Note
SideKernel is still in research preview and not yet ready for production use. Use it responsibly. Please read the [**Paper**](https://sidekernel.com/sidekernel.pdf) or the [**sidekernel.com**](https://sidekernel.com) to learn more.
## Install
Tested on M1 and M4 (macOS 26.2); other Apple silicon chips should work.
Install with `brew` (recommended)
```
brew tap minoansecurity/sidekernel https://github.com/minoansecurity/sidekernel && brew trust --formula minoansecurity/sidekernel/sidekernel
brew install sidekernel
```
Install directly from source:
```
rustup target add aarch64-unknown-linux-musl
git clone https://github.com/minoansecurity/sidekernel
cd sidekernel
make install
```
The first run builds the root filesystem so it might take a minute or two.
## Usage
**On the host** (from a project folder):
```
sk # launch an ephemeral microVM, current directory mounted
sidekernel # (alias: sk)
sclaude # launch a sandbox and start Claude Code directly
```
Coming soon: `scodex`, `sgemini`, `sgrok`, and more.
**Inside the sandbox:**
```
sk-drop <host-path> # copy a host file into the sandbox (requires approval on the host)
sk-net on/off # block all outbound traffic
save # persist installed packages across sandboxes
fightsong # Print's Georgia Tech's fight song on the terminal π (alias: ramblinwreck)
```
You can also **drag and drop** files directly into Claude Code.
**Limitations**
- The agent may read, edit or destroy anything in the mounted directory.
- A malicious agent can open ports to the host, exposing malicious services.
- Only Claude Code is integrated; other harnesses such as Codex are planned.
- SideKernel's security rests on its architecture, but the implementation has not had a formal security review.
- SideKernel is not yet notarized (it is self-signed).
The full list is in the [paper](https://sidekernel.com/sidekernel.pdf) and on the [website](https://sidekernel.com/).
## License
SideKernel is open-source software, licensed under the [Apache License, Version 2.0](https://github.com/minoansecurity/sidekernel/blob/main/LICENSE). | dimiprasakis | 1 | 0 |
| π§ echo.github β | Original work by the poster (HN user dimiprasakis = Dimitrios Prasakis), announced via Show HN. README: "SideKernel is a usable sandbox for | Dimitrios Prasakis (Minoan Security / Georgia Tech MSc Cybersecurity capstone) | β | β |
| π§ hn | Show HN: Autobox β Make your agents sandbox themselves | freakynit | 2 | 2 |
| π§ hn | Show HN: Spens sandboxed, observable coding agents | floydhead01 | 1 | 0 |
| π§ hn | NVX: An Ultra-Light Micro-VM Sandbox from Microsoft | jeswin | 4 | 0 |
| π reddit | I let Claude Code work in a sandbox that can only reach the hosts I allow, and every connection it makes or tries gets logged ClaudeAI | ilai456 | 1 | 6 |
Interpretation history
2026-10-07T04:24:09Z
OpenRod β a host-allowlisted, egress-logged Claude Code sandbox surfaced on Reddit β is the proliferation pattern's first entrant from a second community (HNβGitHubβReddit) and fills the observability/egress axis with a deny-by-default design that is the doctrinal inverse of SideKernel's standing-credential config passthrough; demand stays at zero everywhere, so the frame remains proliferation-without-adoption, now confirmed as cross-community rather than an HN-local cluster.
2026-10-07T03:33:13Z
evidence attached: reddit.post.1wzixdy β OpenRod's host-allowlisted, egress-logged sandbox for Claude Code is an independent tool indicating local-agent containment is spreading as a pattern, even if a different layer than microVM.
2026-10-03T07:11:50Z
Microsoft's NVX is the first megavendor-tier entrant in local-agent microVM containment, completing corroboration across every vendor tier (hobby β indie β commercial β platform-native β megavendor) and sharpening the case's meaning: standardization looks increasingly incumbents'-to-lose, demoting SideKernel's ergonomics bet toward a dated receipt unless it ships multi-harness support or a security review. State stays corroborated rather than accelerating because every launch including NVX is tractionless β supply-side proliferation with zero adoption, discussion, or scrutiny.
2026-10-03T06:30:14Z
evidence attached: hn.story.49941250 β Microsoft shipping an ultra-light micro-VM sandbox independently corroborates microVM containment becoming a standard local-agent isolation pattern (agentic-security is hot).
2026-10-02T14:44:05Z
grounded: converges/medium β Converges with the Give the Agent a Workshop thesis β an unrelated third party ships a microVM reversibility membrane whose explicit design bet is that containm
2026-10-02T14:37:20Z
Spens (independent Docker+mitmproxy sandbox with traffic observability and out-of-the-box multi-harness support for pi/opencode/claude/codex) makes three tractionless first-party launches in four days, recasting the two-sided bet into three-axis differentiation β guarantee strength (SideKernel) vs frictionless weakness (Autobox) vs observability+multi-harness (Spens) β with the market already supplying SideKernel's missing multi-harness support elsewhere. The case now tracks proliferation-without-adoption: the periphery keeps forming while no entrant shows users or any security scrutiny, and SideKernel's individual window is narrowing even as the pattern's evidence base solidifies.
2026-10-02T14:26:17Z
evidence attached: hn.story.49933266 β Independent Docker+mitmproxy sandbox with traffic observability for coding agents is corroboration that local agent-containment tooling is a spreading pattern.
2026-10-01T12:00:53Z
Autobox attach reframes the case from 'one indie entrant in a crowded niche' to one pole of an explicit two-sided bet on sandbox-adoption friction: SideKernel's ergonomic strong containment vs. Autobox's deliberately weaker zero-setup containment, whose own pitch concedes the hesitancy SideKernel's usability bet exists to dissolve. SideKernel's own numbers stay at nil (1 pt / 0 comments at day 4; launch peak ~4.3 pts/h decayed to ~0.3), so adoption and any security scrutiny of the unreviewed, unnotarized binary remain entirely unstarted β the case lives on periphery formation, not its own traction.
2026-10-01T11:26:10Z
evidence attached: hn.story.49920001 β Released self-sandboxing tool attacks the same sandbox-adoption-friction problem with a weaker-guarantee alternative, directly contextualising whether lightweight local-agent containment becomes standard.
2026-09-29T11:49:38Z
origin walked (opencode/cheap-glm, conf 0.95): anchor hn.story.49891008 -> echo.github.3f33363a65 by Dimitrios Prasakis (Minoan Security / Georgia Tech MSc Cybersecurity capstone)
2026-09-29T11:47:34Z
grounded: converges/medium β Converges with the workshop thesis in his Give the Agent a Workshop ebook β disposable Linux microVM as the reversibility membrane around an expansive agent, go
2026-09-29T11:40:28Z
case created β First-party Show HN release of an installable macOS coding-agent microVM sandbox, a distinct claim from Brig and other existing sandbox cases, in a hot band.
Decision trace
- 10-11 14:33review_screenjev screen: no material development (noul=0.13)
- 10-08 00:59attention_routeThe editor compared this story and chose to keep watching.
- 10-07 15:24repriceOpenRod β a host-allowlisted, egress-logged Claude Code sandbox surfaced on Reddit β is the proliferation pattern's first entrant from a second community (HNβGitHubβReddit) and fills the observab
- 10-07 14:33attachOpenRod's host-allowlisted, egress-logged sandbox for Claude Code is an independent tool indicating local-agent containment is spreading as a pattern, even if a different layer than microVM.
- 10-07 14:27propose_attachOpenRod's host-allowlisted, egress-logged sandbox for Claude Code is an independent tool indicating local-agent containment is spreading as a pattern, even if a different layer than microVM.
- 10-03 17:11repriceMicrosoft's NVX is the first megavendor-tier entrant in local-agent microVM containment, completing corroboration across every vendor tier (hobby β indie β commercial β platform-native β megavend
- 10-03 16:30attachMicrosoft shipping an ultra-light micro-VM sandbox independently corroborates microVM containment becoming a standard local-agent isolation pattern (agentic-security is hot).
- 10-03 16:29propose_attachMicrosoft shipping an ultra-light micro-VM sandbox independently corroborates microVM containment becoming a standard local-agent isolation pattern (agentic-security is hot).
- 10-03 00:44repriceSpens (independent Docker+mitmproxy sandbox with traffic observability and out-of-the-box multi-harness support for pi/opencode/claude/codex) makes three tractionless first-party launches in four days
- 10-03 00:44groundConverges with the Give the Agent a Workshop thesis β an unrelated third party ships a microVM reversibility membrane whose explicit design bet is that containment only earns adoption by disappearing
- 10-03 00:26attachIndependent Docker+mitmproxy sandbox with traffic observability for coding agents is corroboration that local agent-containment tooling is a spreading pattern.
- 10-03 00:24propose_attachIndependent Docker+mitmproxy sandbox with traffic observability for coding agents is corroboration that local agent-containment tooling is a spreading pattern.
- 10-01 22:00repriceAutobox attach reframes the case from 'one indie entrant in a crowded niche' to one pole of an explicit two-sided bet on sandbox-adoption friction: SideKernel's ergonomic strong contain
- 10-01 21:26attachReleased self-sandboxing tool attacks the same sandbox-adoption-friction problem with a weaker-guarantee alternative, directly contextualising whether lightweight local-agent containment becomes stand
- 10-01 21:26propose_attachReleased self-sandboxing tool attacks the same sandbox-adoption-friction problem with a weaker-guarantee alternative, directly contextualising whether lightweight local-agent containment becomes stand
- 09-29 21:49promote_anchororigin walk conf 0.95
- 09-29 21:47groundConverges with the workshop thesis in his Give the Agent a Workshop ebook β disposable Linux microVM as the reversibility membrane around an expansive agent, goal-world isolation made a shippable prod
- 09-29 21:40createFirst-party Show HN release of an installable macOS coding-agent microVM sandbox, a distinct claim from Brig and other existing sandbox cases, in a hot band.