Skip to main content
Cybersecurity

AWS Unveils Open-Source Sandbox to Tame Rogue AI Agents

Futuristic robotic form sits prominently in a bright server room with rows of computer workstations.

"Agents increasingly run in ‘YOLO mode,’ approving every action without human review," the AWS team wrote in its announcement, summing up the precise risk Strands Box is designed to contain.

Strands Box: OS-level sandbox plus policy enforcement

AWS has released Strands Box as an open-source sandbox that combines OS-level isolation with a separate policy and event system to control autonomous AI agents. AWS frames the problem this way: traditional containers and microVMs provide strong isolation but lack contextual rule enforcement, so an agent that gains access to a tool can still act unchecked — deleting databases, pushing to repos, or accessing the internet. Box aims to add that missing layer by enforcing policies externally and deterministically rather than relying on the agent's own compliance.

Dogwood Local Engine: giving policies temporal awareness

Strands Box integrates the Dogwood Local Engine so the policy layer has temporal awareness and an event history. That allows the engine to evaluate proposed tool calls not only against what an agent wants to do now, but against what it has already done. AWS illustrated the approach with a concrete example: an agent could be allowed to post status updates to Slack, but no more than three times every ten minutes to prevent spamming human operators. AWS also noted Box can limit when an agent may perform a Git push or put a cap on API calls that might otherwise generate unexpectedly high costs.

Interpreters: Strands Shell, Monty for Python, and clearer agent intent

Strands Box includes Strands Shell and Monty for Python, which expose shell and Python operations to the Dogwood policy engine and event history. Marc Brooker, an AWS VP and distinguished engineer and one of the developers behind Dogwood and Strands Box, told The Register that the interpreters are key to making agentic behavior more intelligible and therefore to writing more precise policies to block dangerous actions. "Box’s Shell and Python interpreters expose operations such as file deletions, while its gateways expose API requests and tool calls," Brooker said. By surfacing those operations into the policy context, Box lets policies account for both the action being attempted and earlier activity.

Policy enforcement and developer responsibility

According to AWS, Box enforces the policies developers configure "deterministically, and the agent can't talk its way around these rules." The company emphasized that enforcement does not mean removing human responsibility: Brooker and AWS spokespeople both stressed developers must decide what access to grant and where human review remains necessary. Brooker further acknowledged that even with correctly configured permissions, an agentic action can still produce an unwanted result, underscoring that Box constrains agent behavior but does not absolve developers from careful configuration and oversight.

Availability: GitHub release, macOS client now; Linux and Windows status

Strands Box is available on GitHub today, but the initial client works only on macOS. AWS told The Register that Linux support is in development and a Windows client is "on our radar," though neither platform has a planned release date. The company also said deployment targets such as AgentCore, ECS, and Kubernetes are planned but not yet delivered.

What this means for developers, security teams, and procurement

  • Developers: Interpreters (Shell and Python) should make agentic actions more intelligible and allow writing finer-grained policies; developers must still configure those policies and decide where human review is required.
  • Security teams and SREs: The Dogwood engine's temporal awareness and event history enable caps on repetitive actions (for example, three Slack posts in ten minutes) and limits on costly API calls or Git pushes, giving teams concrete levers to reduce operational risk.
  • Procurement and platform teams: The initial macOS-only client and the absence of release dates for Linux and Windows mean wider adoption will depend on AWS delivering the planned platform clients and the promised deployments to AgentCore, ECS, and Kubernetes.

AWS presents Strands Box as a practical tool to add rule-based, time-aware constraints where simple isolation has proved insufficient. The open-source release on GitHub puts the components — Strands Box, Dogwood, Strands Shell and Monty for Python — into the hands of developers today, but adoption will hinge on broader platform support and on developers accepting the continued responsibility of configuring policies and human review. As Brooker put it, "Agent safety is an area where the industry still has significant work to do, and we're committed to continuing to invest in it, both inside the AWS cloud and in open source."

Original report — The Register