AWS Strands Box Tames AI Agents with Open-Source Sandbox
AWS introduces Strands Box, an open-source AI agent sandbox that uses OS-level isolation and temporal awareness to prevent autonomous agents from executing unintended or harmful actions.

Amazon Web Services (AWS) has unveiled Strands Box, a new open-source AI agent sandbox designed to address the growing risks associated with autonomous agents operating in "YOLO mode" – a state where they approve every action without human review. This innovative solution aims to provide developers with enhanced control and visibility over AI agent behavior, mitigating potential disasters such as accidental data deletion or excessive resource consumption.
Traditional sandboxing methods, often relying on containers or microVMs, offer strong isolation but lack the contextual enforcement needed to govern agent actions effectively. Strands Box tackles this limitation by integrating AWS's existing open-source AI control tools, including the Dogwood Local Engine. This engine imbues the policy engine with temporal awareness, allowing it to evaluate tool calls not only based on the agent's immediate intent but also on its past actions.
For instance, Strands Box can enforce policies that prevent an AI agent from spamming users by limiting its Slack posts to a maximum of three every ten minutes. Similarly, it can control when an agent is permitted to perform a Git push or cap the number of API calls to prevent runaway costs. This granular control is crucial for ensuring that AI agents operate within defined operational and financial boundaries.
The Strands Box ecosystem also includes Strands Shell and Monty for Python. These components extend the Dogwood policy engine's reach to shell and Python operations, making agentic actions more transparent to developers. By exposing operations like file deletions, API requests, and tool calls, Strands Box enables developers to write more precise policies that account for both the attempted action and the agent's historical activity.
Marc Brooker, AWS VP and distinguished engineer, emphasized that Strands Box enforces configured rules deterministically, preventing agents from circumventing security measures. "Box enforces the policies developers configure, deterministically, and the agent can't talk its way around these rules," Brooker stated. However, he also cautioned that even with proper permissions, unintended results can occur, underscoring the continued need for human oversight.
AWS's commitment to agent safety is reflected in its ongoing investment in open-source tools. Strands Box, along with related projects like Dogwood and the Dogwood Local Engine, represents a significant step towards finding a balance between empowering AI agents and establishing robust boundaries to prevent catastrophic failures. The company aims to foster a more secure environment for AI development and deployment, both within the AWS cloud and through open-source contributions.
Currently, Strands Box is available on GitHub, with initial support for macOS. AWS is actively developing Linux support and has a Windows client on its radar, though specific release dates have not yet been announced. Future plans also include deployment options for platforms such as AgentCore, ECS, and Kubernetes, further expanding the reach and applicability of this AI safety solution.