
AWS Launches Strands Box, an Open Source Sandbox for AI Agents
Strands Box, now in developer preview, combines OS-level isolation with Dogwood policy enforcement to govern what AI agents can do across files, shell, Python, MCP tools, and network traffic.
AWS has launched Strands Box in developer preview, an open source sandbox licensed under Apache 2.0 that combines operating system isolation with fine-grained policies governing what AI agents can do. The project builds on Dogwood, an open source policy language, and the Dogwood Local Engine, which evaluates policies against an agent's requested actions and recorded history.
Containment plus policy
Strands Box relies on two layers. Containment uses OS-level isolation, such as macOS Seatbelt, to define what an agent can reach on the host machine and the network, establishing a hard boundary. Within that boundary, policy governs which actions the agent can perform. Policy is applied at multiple enforcement points: network egress, a Python interpreter, a Shell interpreter, and a broker for Model Context Protocol servers. These points govern which files the agent can read or modify, which commands it can run, which HTTP methods and paths it can access, and which MCP tools it can call.
The box embeds two code interpreters, Strands Shell and Monty for Python, which run outside the sandbox and intercept operations such as filesystem access or network calls, routing them through the policy engine. Every enforcement point reports actions uniformly, so a file read through a shell command or a Python script is an fs:read event, and an HTTP request from curl or Python is an http:request event. This lets a single rule connect an earlier action through one tool with a later action through another.
Credentials and configuration
All outbound traffic passes through an egress gateway that raises an http:request decision and forwards only what policy permits. The gateway can also attach credentials: for configured API-key routes, the agent receives a placeholder token that the gateway replaces with the real secret before forwarding, so the secret never enters the agent's environment. Supported methods include Bearer tokens, custom headers, HTTP Basic, query parameters, and AWS SigV4 signing with credentials obtained outside the agent.
A box is configured through two files. box.toml describes the environment: the agent's command, working directory, filesystem access, tools, MCP servers, and credential bindings. policy.dw contains the Dogwood rules, written in Cedar-style syntax with permit or forbid statements over an action and conditions in when blocks.
Temporal policies
Dogwood's temporal operators let authorization depend on what the agent has already done. In one example, a rule permits Slack posts to a specific endpoint but forbids further posts once the box has recorded three successful 200 responses within ten minutes. Refusals return an HTTP 403 naming the rule by its identifier and description, so the agent can adjust its behavior. The rule counts only successful responses, so denied attempts do not count toward the limit.
What's next
AWS plans to expand OS support beyond macOS, build a CLI that detects installed agent harnesses and generates a baseline box.toml and policy, and let developers package agents with Box for deployment to platforms such as Amazon Bedrock AgentCore, ECS, or Kubernetes. The company also plans to extend Dogwood with liveness rules describing what must eventually happen. A Policy Authoring agent skill is available to help write Dogwood policies, and the project is available on GitHub at github.com/strands-agents/box.
Sources: The Register · Aws · Strands Agents
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.