{"repo":"VirtusLab/sandcat","free":true,"listed":false,"github":"https://github.com/VirtusLab/sandcat","clone":"git clone https://github.com/VirtusLab/sandcat.git","description":"A Docker & dev container setup for securely running AI agents in `--dangerous` mode. All container traffic is routed through a transparent mitmproxy, enforcing network access rules and injecting secrets.","language":"Shell","stars":186,"topics":["agents","ai","autonomous","claude","devcontainer","security","vscode"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"Sandcat Sandcat is a Docker & dev container setup for securely running AI agents. The environment is sandboxed, with controlled network access and transparent secret substitution. All of this is done while retaining the convenience of working in an IDE like VS Code. All container traffic is routed through a transparent mitmproxy via WireGuard, capturing HTTP/S, DNS, and all other TCP/UDP traffic without per-tool proxy configuration. A straightforward allow/deny list-based engine controls which network requests go through, and a secret substitution system injects credentials at the proxy level so the container never sees real values. This repository contains: a bash CLI to initialize the sandbox for a project, copying and customizing the necessary files (see cli/ ) reusable proxy definitions under cli/templates/devcontainer/sandcat/ : Dockerfile.wg-client , compose-proxy.yml , and scripts/ that perform the network filtering & secret substitution template application and dev container configuration under cli/templates/devcontainer/ : Dockerfile.app , compose-all.yml , devcontainer.json . This should be fine-tuned for each project and specific development stack, to install required tools and dependencies. Sandcat can be used as a devcontainer setup, or standalone, providing a shell for secure development. Sandcat is part of Visdom, VirtusLab's AI-driven software delivery infrastructure. Quick start 1. Install sandcat CLI The CLI is a helper script and thin wrapper around docker-","default_branch":null,"files":null,"tree":[],"storefront":"/r/VirtusLab","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/VirtusLab/sandcat/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}