sandvault — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by webcoyote · Codex Skill · ★ 413

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is sandvault safe to install? View the security audit →

About sandvault

SandVault - Run Claude Code, OpenAI Codex, Google Gemini and shell commands safely in a sandboxed macOS user account SandVault () manages a limited user account to sandbox shell commands and AI agents, providing a lightweight alternative to application isolation using virtual machines. Features AI ready - Includes Claude Code, OpenAI Codex, Google Gemini Fast context switching - No VM overhead; instant user switching Passwordless - switch accounts without a prompt (after setup) Shared workspace - joint access to Clean uninstall - Complete removal with Quick Links To run or see Sandboxing xcodebuild and swift for details. To run other sandboxed applications inside sandvault, use the option. See Sandboxing other apps for details. It's not possible to run GUI applications from within the sandbox; see Running GUI Applications for details. Security Model SandVault has limited access to your computer: Cannot access your home directory Runs with standard user privileges Cannot modify system files Has no access to mounted drives writable: /Users/Shared/sv-$USER -- only accessible by you & sandvault-$USER writable: /Users/sandvault-$USER -

claude-codemacosopenai-codexsandbox

Quick Facts

Stars413
Forks26
LanguageShell
CategoryCodex Skill
LicenseApache-2.0
Quality Score73.3715548578965/100
Open Issues1
Last Updated2026-09-14
Created2025-09-12
Platformsclaude-code, cli, codex, gemini
Est. Tokens~13k

sandvault alternative? Top 6 similar tools

Looking for a sandvault alternative? If you're comparing sandvault with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • vllm-mlx by waybarrios · ⭐ 1.6k

    High-performance OpenAI and Anthropic compatible LLM inference server for Apple Silicon. Native MLX, continuou

  • sandbox-agent by rivet-dev · ⭐ 1.6k

    Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

  • kicad-happy by aklofas · ⭐ 1.2k

    AI coding agent skills for KiCad electronics design. Works with Claude Code and OpenAI Codex. Analyze schemati

  • vm0 by vm0-ai · ⭐ 1.2k

    Zero, your trustworthy AI teammate for real work.

  • Mysti by DeepMyst · ⭐ 1.1k

    AI coding dream team of agents for VS Code. Claude Code + openai Codex collaborate in brainstorm mode, debate

  • agent-sessions by jazzyalex · ⭐ 889

    Local-first macOS app to browse, search, analyze, and resume supported AI coding-agent session history across

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular Shell Agent Tools

Frequently Asked Questions

What is sandvault?

sandvault is Run AI agents isolated in a macOS user account and sandbox-exec. Configured to run Claude Code, OpenAI Codex, Cursor Agent, Google Gemini.. It is categorized as a Codex Skill with 413 GitHub stars.

What programming language is sandvault written in?

sandvault is primarily written in Shell. It covers topics such as claude-code, macos, openai-codex.

How do I install or use sandvault?

You can find installation instructions and usage details in the sandvault GitHub repository at github.com/webcoyote/sandvault. The project has 413 stars and 26 forks, indicating an active community.

What license does sandvault use?

sandvault is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to sandvault?

The top alternatives to sandvault on Agent Skills Hub include vllm-mlx, sandbox-agent, kicad-happy. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools