You trust your AI agent with your repo. Do you trust it with your SSH keys, your ~/.aws, your dotfiles? Most people running Claude Code, Codex, or OpenCode don’t think about it until it’s too late — and by then the agent has already read everything it could reach.
Greywall (Apache 2.0, Go) is a container-free, deny-by-default sandbox built specifically for AI coding agents on Linux and macOS. No Docker, no VMs — kernel-enforced isolation via Bubblewrap namespaces, Landlock, Seccomp BPF, eBPF monitoring, and a TUN-based network capture.
What it actually does
The core idea is inverted from how you normally run agents: instead of letting the agent see everything and hoping it behaves, you give it nothing and explicitly allow what it needs.
# Sandbox a command — network + filesystem denied by default
greywall -- curl https://example.com
# Run an AI agent with a built-in profile
greywall -- claude
# Observe first, enforce later
greywatch -- opencode
# Learn what an agent needs, then auto-generate a least-privilege profile
greywall --learning -- opencode
What makes it genuinely good
- Deny-by-default filesystem — only the working directory is reachable unless you allow more. Your secrets stay out of reach.
- Network isolation — all traffic is blocked or routed through
greyproxy, a transparent proxy with a live allow/deny dashboard. - Command blocking — dangerous commands like
rm -rf /andgit push --forceare denied outright. - Built-in agent profiles — one-command setup for Claude Code, Cursor, Codex, Aider, Goose, Gemini, OpenCode, Amp, Cline, Copilot, and more.
- Learning mode — traces filesystem access and auto-generates a least-privilege profile, so you don’t have to guess what the agent needs.
- Observability mode —
greywatchruns with everything allowed and logs it all, so you can see exactly what a tool does before you lock it down. - No containers — kernel-enforced, so no Docker overhead or image management.
Why it matters
The real workflow is greywatch → --learning → enforce. Watch what your agent does, let it teach you the access it needs, then lock it down to exactly that. It turns “trust the agent” into “audit the agent,” which is the only sane posture when a tool has full read access to your machine.
The one-line pitch
Greywall gives AI coding agents a least-privilege cage — kernel-enforced, container-free, with a learning mode so you don’t have to configure it by hand.
Install
# Linux / macOS
curl -fsSL https://raw.githubusercontent.com/GreyhavenHQ/greywall/main/install.sh | sh
Next step
Try greywatch -- opencode on a scratch project to see what your agent touches, then flip to greywall --learning -- opencode to generate a real profile. It’s young (286★) but the security model is sound and it’s actively maintained.