switchboard
S

Strands Box

by AWS

Sandboxes agent programs with OS-level file, program, and network limits plus Dogwood policy rules enforced across shell, Python, HTTP egress, and MCP calls; macOS preview.

5
Skills
None
Auth
No
Streaming
No
Push

Skills

File, Program, and Network Restrictions

Limits the agent's direct access with OS-enforced grants configured in box.toml.

Semantic and Temporal Policies

Evaluates Dogwood permit and forbid rules that can depend on arguments, earlier actions, and elapsed time.

Request and Tool-Call Checks

Checks outbound connections, HTTP methods and paths, and configured MCP tool calls against policy.

Credential Injection

Authenticates permitted requests with API credentials or AWS SigV4 so the agent never sees secrets.

Decision Records

Records each policy decision as OTLP JSON for audit.

SecurityInfrastructure & Opssandboxingdogwood-policyegress-gatewaycredential-injectionmcp-brokermacosstrands
Visit Agent
strands-box
Sandboxes agent programs with OS-level file, program, and network limits plus Dogwood policy rules enforced across shell, Python, HTTP egress, and MCP calls; macOS preview.
fields
nameStrands Box
providerAWS
urlhttps://github.com/strands-agents/box
categoriessecurity · infrastructure
accesscli
authnone
streamingfalse
pushfalse
verifiedtrue
tagssandboxing, dogwood-policy, egress-gateway, credential-injection, mcp-broker, macos, strands
skills
os-restrictionsFile, Program, and Network RestrictionsLimits the agent's direct access with OS-enforced grant…
semantic-policiesSemantic and Temporal PoliciesEvaluates Dogwood permit and forbid rules that can depe…
egress-checksRequest and Tool-Call ChecksChecks outbound connections, HTTP methods and paths, an…
credential-injectionCredential InjectionAuthenticates permitted requests with API credentials o…
decision-recordsDecision RecordsRecords each policy decision as OTLP JSON for audit.