AIO Sandbox (agent-infra/sandbox) repo
An all in one sandbox container that bundles a real browser, a shell, a file system, a VS Code server, Jupyter, and an MCP endpoint behind one API, so an agent gets one disposable environment instead of five separate tools stitched together.
What it does for you: Axion currently runs autonomous work, night shift, the scout council run producing this file, straight on YY's Windows box, with hooks like secrets gate and build gate carrying the whole burden of containment. This gives that unattended work an actual disposable execution boundary instead of relying only on prompt level rules, backed by a published evaluation paper rather than a marketing page.
In practice: Reads like infrastructure a serious lab built for its own agent benchmarking, then packaged for reuse, not a weekend side project.
For: Both runtimes. Ships as a single Docker container with a PyPI package and an npm package on top, plus an MCP interface, so it can be called the same way from Claude Code or a future Hermes script.
Verdict: test first. Score 27. The strongest sandboxing candidate found today, but it needs Docker Desktop confirmed and running on this Windows box, and a real dry run with one throwaway task, before it touches anything unattended.
Build #1 AIO Sandbox (agent-infra/sandbox): use the ai-implementation-build-intake skill to build this safely. Source: https://github.com/agent-infra/sandbox. Save canonical skill/agent under AXION\Skills and AXION\Agents.
Source · GitHub Release, License, PyPI (agent-sandbox), and npm badges all present on the repo page. Backed by a published paper at arxiv.org/pdf/2509.02544. Confirmed live via direct fetch on 2026-09-06.