Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by holtwick · Claude Skill · ★ 102
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is bx-mac safe to install? View the security audit →
📦 bx Put your AI in a box. Launch VSCode, Claude Code, a terminal, or any command in a macOS sandbox — your tools can only see the project you're working on. Not a vault, but a reasonable safety net. 🤔 Why? AI-powered coding tools like Claude Code, Copilot, or Cline run with broad file system access. A misguided tool call or hallucinated path could accidentally read your SSH keys, credentials, tax documents, or private photos. bx wraps any application in a macOS sandbox () that blocks access to everything except the project directory you explicitly specify. No containers, no VMs, no setup — just one command. That's it. 🎉 VSCode opens with full access to and nothing else. Read the blog post for more background on the motivation behind bx. Need multiple directories? No problem: ✅ What it does 🔒 Blocks , , , and all other personal fol
| Stars | 102 |
| Forks | 3 |
| Language | TypeScript |
| Category | Claude Skill |
| License | MIT |
| Quality Score | 66.4993228056771/100 |
| Open Issues | 2 |
| Last Updated | 2026-09-18 |
| Created | 2026-03-28 |
| Platforms | claude-code, cli, node, vscode |
| Est. Tokens | ~20k |
These tools work well together with bx-mac for enhanced workflows:
Looking for a bx-mac alternative? If you're comparing bx-mac with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Let AI agents message, watch, and spawn each other across terminals. Claude Code, Codex, Antigravity CLI, Curs
Ultra-fast token & cost tracker for LLM Token Usage (e.g. Claude Code)
One workspace all your AI agents can read and write. Encrypted client-side, model-agnostic, gone 24h after the
Local-first AI knowledge layer. Extract architecture, query from any AI tool via MCP. Private by architecture.
Transform your Claude Code terminal with atomic precision statusline. Features flexible layouts, real-time cos
TUI / CLI config manager for agentic harnesses (Amp, Claude Code, Opencode, Goose, Copilot CLI, Crush, Droid)
Explore other popular claude skill tools:
bx-mac is Sandbox any macOS app — only your project directory stays accessible. It is categorized as a Claude Skill with 102 GitHub stars.
bx-mac is primarily written in TypeScript. It covers topics such as claude-code, cli, developer-tools.
You can find installation instructions and usage details in the bx-mac GitHub repository at github.com/holtwick/bx-mac. The project has 102 stars and 3 forks, indicating an active community.
bx-mac is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to bx-mac on Agent Skills Hub include hcom, toktrack, vnsh. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: