bx-mac — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by holtwick · Claude Skill · ★ 102

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is bx-mac safe to install? View the security audit →

About bx-mac

📦 bx Put your AI in a box. Launch VSCode, Claude Code, a terminal, or any command in a macOS sandbox — your tools can only see the project you're working on. Not a vault, but a reasonable safety net. 🤔 Why? AI-powered coding tools like Claude Code, Copilot, or Cline run with broad file system access. A misguided tool call or hallucinated path could accidentally read your SSH keys, credentials, tax documents, or private photos. bx wraps any application in a macOS sandbox () that blocks access to everything except the project directory you explicitly specify. No containers, no VMs, no setup — just one command. That's it. 🎉 VSCode opens with full access to and nothing else. Read the blog post for more background on the motivation behind bx. Need multiple directories? No problem: ✅ What it does 🔒 Blocks , , , and all other personal fol

claude-codeclideveloper-toolsmacosprivacysandboxsecurityterminalvscodexcode

Quick Facts

Stars102
Forks3
LanguageTypeScript
CategoryClaude Skill
LicenseMIT
Quality Score66.4993228056771/100
Open Issues2
Last Updated2026-09-18
Created2026-03-28
Platformsclaude-code, cli, node, vscode
Est. Tokens~20k

Compatible Skills

These tools work well together with bx-mac for enhanced workflows:

  • apple-notes-mcp — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (52%)
  • claude-warden — semantic(0.17)+complementary+similar_pop+shared_platform (46%)
  • apple-docs-mcp — semantic(0.18)+complementary+rare_topics+same_lang+shared_platform (46%)

bx-mac alternative? Top 6 similar tools

Looking for a bx-mac alternative? If you're comparing bx-mac with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • hcom by aannoo · ⭐ 490

    Let AI agents message, watch, and spawn each other across terminals. Claude Code, Codex, Antigravity CLI, Curs

  • toktrack by mag123c · ⭐ 190

    Ultra-fast token & cost tracker for LLM Token Usage (e.g. Claude Code)

  • vnsh by raullenchai · ⭐ 156

    One workspace all your AI agents can read and write. Encrypted client-side, model-agnostic, gone 24h after the

  • TaskWing by josephgoksu · ⭐ 87

    Local-first AI knowledge layer. Extract architecture, query from any AI tool via MCP. Private by architecture.

  • claude-code-statusline by rz1989s · ⭐ 477

    Transform your Claude Code terminal with atomic precision statusline. Features flexible layouts, real-time cos

  • bridle by neiii · ⭐ 433

    TUI / CLI config manager for agentic harnesses (Amp, Claude Code, Opencode, Goose, Copilot CLI, Crush, Droid)

More Claude Skill Tools

Explore other popular claude skill tools:

View all Claude Skill tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is bx-mac?

bx-mac is Sandbox any macOS app — only your project directory stays accessible. It is categorized as a Claude Skill with 102 GitHub stars.

What programming language is bx-mac written in?

bx-mac is primarily written in TypeScript. It covers topics such as claude-code, cli, developer-tools.

How do I install or use bx-mac?

You can find installation instructions and usage details in the bx-mac GitHub repository at github.com/holtwick/bx-mac. The project has 102 stars and 3 forks, indicating an active community.

What license does bx-mac use?

bx-mac is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to bx-mac?

The top alternatives to bx-mac on Agent Skills Hub include hcom, toktrack, vnsh. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Claude Skill tools