AWS previews Strands Box for controlling AI agent actions
Strands Box combines local isolation with rules based on earlier actions. Its macOS preview leaves direct file grants outside policy history.

AWS introduced Strands Box on October 7 as a developer preview. The open source sandbox combines operating system isolation with policies that can consider an AI agent’s earlier actions.
The project repository says developers choose the agent program to run. Box checks operations routed through its shell and Python interpreters, network gateway and Model Context Protocol broker. Checked operations require permission, and a matching prohibition overrides an allowance.
One example policy limits Slack posting to three HTTP 200 responses in ten minutes. The gateway can also add credentials to permitted requests without exposing the underlying secrets to the agent. These are configurable controls rather than independent test results.
The preview currently runs locally on macOS with Apple silicon. Its getting started guide requires macOS 15 or later and warns that existing agents may need network configuration changes. Linux support remains planned.
The security documentation draws an important boundary. Direct filesystem grants are enforced by the operating system and produce no individual policy decision or history record. Applying policy to file operations requires mediated access rather than broad direct grants.
Allowed network destinations still provide a route for sending readable information. Box supplies no isolation between hosted tenants and sets no CPU, memory or disk limits. ByteForward has not tested the preview.



