brig docs

Compare

Brig and the agents' own sandboxes

On this page

Brig puts the whole agent in a microVM with a kernel of its own, before the agent starts, with your project and nothing else, a network rule you write, and its login from your keychain. Claude Code, Codex, Cursor and Gemini CLI each carry a sandbox of their own, built from Seatbelt on macOS and from bubblewrap, Landlock or a container on Linux, around the commands the agent runs.

The built-in sandboxes need no install. This page states what each one covers, and what Brig adds around it. The two work together: an agent can run its own sandbox inside a Brig guest. Brig compared puts both beside the other tools.

At a glance #

Brig Claude Code Codex Cursor Gemini CLI
Covers The whole agent and every process it starts The Bash tool and its children Every command the agent runs Terminal commands Each tool call. The older mode covers the whole CLI
Kernel One kernel per sandbox, under a hypervisor The host kernel The host kernel The host kernel The host kernel. gVisor adds a user-space kernel on Linux
macOS hvi on Hypervisor.framework Seatbelt Seatbelt Seatbelt Seatbelt, or Docker
Linux A microVM on KVM bubblewrap bubblewrap and seccomp Landlock and seccomp bubblewrap per tool. The older mode runs the whole CLI in Docker, Podman, gVisor or LXC
Host files The project and the guest home, and nothing else from the host Reads the whole disk. Writes the project and a temp directory Reads the whole disk. Writes the workspace, with .git and .codex read-only Reads the whole disk. Writes the workspace Container: the project. Seatbelt: broad reads, project writes
Network An egress policy of hosts and ranges, enforced outside the guest A proxy on the host with a domain list Off by default. A proxy with a domain list is opt-in A domain list, with Cursor's package-manager and code-host domains allowed by default Open by default. A proxy is opt-in
Credentials A secret store, delivered by name as a file. v0.5.0 adds secret brokerage, and the guest then holds a placeholder Denied or masked. Masking needs TLS termination at the proxy auth.json or the keyring readBoundary in sandbox.json decides whether ~/.ssh is readable Variables passed in. gcloud credentials mounted read-only. Other credential files kept out of the container
On by default Yes. Every run is a sandbox No Yes, workspace-write Depends on the run mode No
Unattended run Yes Partial. The sandbox covers shell commands only Yes, codex exec A run mode -s -p
Licence Apache-2.0 Part of Claude Code Apache-2.0 Part of Cursor Apache-2.0

What Brig gives you #

A kernel the host does not share. Under Brig, every command the agent runs makes its system calls to a kernel inside the microVM. hvi, the VMM Brig uses on macOS, treats the guest as hostile and runs inside a Seatbelt profile of its own. The boundary in hvi describes it. A command under Seatbelt or bubblewrap makes its system calls to the host kernel.

The whole agent, not one tool. Brig sandboxes the agent process itself, and every MCP server, hook, language server and subprocess it starts. The guest has the project and the guest home, and no other host directory. Your SSH keys, cloud credentials and browser profile are not readable, because they are not there. What the agent cannot reach states the list and its limits. Claude Code's sandbox covers the Bash tool, and its file tools, hooks, MCP servers and LSP servers run outside it.

A network rule, not a proxy. Brig's egress policy is a list of hosts and ranges. It is enforced at the gateway on macOS and in nftables on Linux, outside the guest, for every protocol. A tool that ignores proxy variables is still filtered. A run on a backend that cannot enforce the policy is refused with exit code 7. --network offline leaves no route out on any backend. See Networking.

Credentials off the host disk. A Brig profile names which secret the agent gets, from a store in the keychain. The agent reads it as a file on a memory-backed mount, and the file does not reach your disk. A profile's deny list keeps a metered key out of the guest's environment. Credentials states each limit, including the refresh token Claude Code needs. Brig v0.5.0 adds secret brokerage, and the guest then holds a placeholder in place of the real value.

Sandboxed by default. Every brig run is a sandbox. There is no setting to turn on, and no command runs outside it. A session keeps the agent's state, and brig rm removes it.

One tool for every agent. Brig ships eight profiles, for Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Grok, OpenCode and a plain Ubuntu shell, and the same policy and secret store apply to each. See Built-in profiles.

What the built-in sandboxes do #

Each tool wraps a command in the operating system's process sandbox before it runs it. On macOS, that is a Seatbelt profile written at runtime. On Linux, Claude Code and Codex start the command under bubblewrap. Cursor uses Landlock and seccomp. Gemini CLI runs each tool under bubblewrap or Seatbelt. Its older mode runs the whole CLI in a Docker or Podman container, or under gVisor.

The filesystem rule has the same shape in each. The command can write the project and a temp directory. It can read everything else. Writes to a short list of files, such as shell startup scripts and git hooks, are denied inside the project too. Claude Code's documentation says that the default "still allows reading credential files".

Claude Code's network rule is a proxy on the host. The sandbox allows a connection to that proxy and nothing else, and the proxy checks the hostname against a list. Codex starts with no network, and its proxy is opt-in. Gemini CLI starts with the network open, and its proxy is opt-in. Cursor starts with its own domain list. Claude Code, Codex and Gemini CLI do not inspect TLS by default, and Cursor does not say. Anthropic's documentation names domain fronting as a way around the list. It also warns that a broad domain such as github.com is a path out for data.

Claude Code's documentation says the sandboxed Bash tool "on its own constrains only shell commands, so it is not sufficient for fully unattended runs". It tells you to run such sessions "inside a container, a VM, or the sandbox runtime". Cursor's agent can rerun a command outside the sandbox when a restriction stops it.

When a built-in sandbox fits #

  • Nothing to install. Turn it on in the tool. Claude Code has /sandbox.
  • Start time. A command starts as a process. Brig boots a kernel once per sandbox.
  • The host's tools. The agent runs on your macOS or Linux, with your compilers, your shell and your editor's language servers.
  • Every Mac. Seatbelt runs on an Intel Mac and on older macOS releases. Brig needs Apple silicon and macOS 15 or newer for its default backend.
  • Credential masking, today. Claude Code's mask setting gives the agent a sentinel and swaps the real value at the proxy. It needs the proxy to terminate TLS, an experimental setting. Brig hands the agent the credential as a file on a memory-backed mount until v0.5.0 adds secret brokerage.

Both at once #

A Brig guest is a Linux machine. An agent's own Linux sandbox can run inside it, when the guest image carries what that sandbox needs, such as bubblewrap for Claude Code. The agent then has two layers, and the outer one does not depend on the inner one. Guest images covers adding a package to an image.

Run Claude Code under each #

Under Brig:

brig run claude ~/code/demo

With Claude Code's own sandbox:

cd ~/code/demo
claude
> /sandbox

Then allow each domain the agent asks for, or set allowedDomains in your settings. Under Brig, the agent's permission mode is the agent's own setting, and the boundary does not depend on it.

Sources #

Read on 2026-10-06.

Type a command, a flag or an error message.