รีวิว Strands Box — sandbox จำกัดสิทธิ์ AI agent แบบ default-deny (Preview บน macOS)
ข้อมูล Repo
strands-agents/box- ภาษา
- Rust
- ดาว
- 312
- สร้างเมื่อ
- แก้ไขล่าสุด
เปลี่ยนสถานะผ่าน API: PATCH /api/reports/1518f339-9480-4d6c-89f1-292f49975cc7
แคปชันสำหรับ Facebook
จะปล่อยให้ agent รันงานบนเครื่องจริง แต่ยังไม่แน่ใจว่ามันจะอ่านไฟล์ไหน รันอะไร หรือออกเน็ตได้แค่ไหน Strands Box จากทีม strands-agents คือ sandbox โอเพนซอร์สสำหรับ AI agent เขียนด้วย Rust ✅ จำกัดไฟล์ โปรแกรม และเครือข่ายที่ agent เข้าถึงได้ ✅ Dogwood policy แบบ default-deny ถ้าไม่มีกฎ permit ก็ถูกปฏิเสธ ✅ policy ชุดเดียวใช้กับ Shell, Python, egress gateway และ MCP broker ✅ credential injection ทำให้ secret ไม่หลุดเข้า agent process ✅ บันทึก policy decisions เป็น OTLP JSON ไว้ตรวจย้อนหลังได้ ตอนนี้อยู่สถานะ Preview รองรับเฉพาะ macOS บน Apple silicon ส่วน Linux อยู่ในแผน เหมาะกับคนที่พร้อมทดสอบของใหม่ 🔗 https://github.com/strands-agents/box #StrandsBox #AIAgents #Sandbox #Security #OpenSource
ภาพปกแบบ HTML สด
แสดงจาก HTML ต้นฉบับที่ใช้สร้างภาพ ดาวน์โหลดเป็น PNG 1080×1350 ได้ทันที
สไตล์ Easy AI
1080×1350แก้ไข 2026-10-11
สไตล์ easy-app
1080×1350แก้ไข 2026-10-11
สรุป
Strands Box เป็น sandbox engine โอเพนซอร์สที่รัน AI agent โดยจำกัดสิ่งที่ execute อ่าน เขียน และออกเน็ตได้ ใช้ OS isolation ร่วมกับ Dogwood policy แบบ default-deny และ credential injection ที่เก็บ secret ไว้นอก agent process ตอนนี้ยังเป็น Preview รองรับเฉพาะ macOS บน Apple silicon
คืออะไร
Strands Box (repo strands-agents/box) เป็น sandbox engine โอเพนซอร์สสำหรับ AI agents โดยเข้ากับแนวคิดที่ว่า agent ควรถูกจำกัดสิ่งที่มันรัน อ่าน เขียน และติดต่อเครือข่ายได้
จุดที่น่าสนใจคือ Box ไม่ได้ผูกกับ agent ตัวใดตัวหนึ่ง ตัว README ระบุว่าเป็น harness-agnostic คุณเลือกเองว่าจะรัน agent program หรือ binary ไหน แล้วตั้งค่าสิทธิ์ในไฟล์ box.toml และเขียน policy ในไฟล์ policy.dw
การบังคับใช้แบ่งเป็นสองชั้น ชั้นแรกคือ OS บังคับ direct access ที่ตั้งไว้ใน box.toml ส่วนอีกชั้นคือ Strands Shell, Monty for Python, egress gateway และ MCP broker จะส่ง operation ที่ตัวเองจัดการไปให้ Dogwood Local Engine ที่ฝังอยู่ประเมิน rule ใน policy.dw โดย Box บังคับคำตัดสิน allow หรือ deny นอก agent process
ปัจจุบันอยู่ในสถานะ Preview รองรับการรันแบบ local บน macOS ที่ใช้ Apple silicon เท่านั้น ส่วน Linux อยู่ในแผน
จุดเด่น
- จำกัดไฟล์, โปรแกรม และเครือข่าย ตัว sandbox ของ agent จำกัด direct access และ Box รายงาน grant ที่ตั้งค่าไว้ตอน startup
- Semantic และ temporal policy: กฎของ Dogwood ขึ้นกับ operation ที่ขอ, argument, action ก่อนหน้า และเวลาที่ผ่านไป โดย operation ที่ผ่านการตรวจจะถูก deny จนกว่าจะมีกฎ permit
- ใช้ policy ชุดเดียวกันครอบทั้ง code และ tools Strands Shell, Monty for Python, egress gateway และ MCP broker ใช้ policy engine และ event history ร่วมกัน ตัวอย่างใน README คือ file read ผ่าน Shell หรือ Python สามารถทำให้ gateway ปฏิเสธ outbound HTTP request ในภายหลังได้
- ตรวจ request และ tool call: egress gateway ตรวจ connections และ HTTP requests รวมถึง method กับ path ส่วน MCP integration ตรวจ tool calls ที่ตั้งค่าไว้และ argument ของมัน
- Credential injection: gateway authenticate request ที่ถูกอนุญาตด้วย API credentials หรือ AWS SigV4 signing ที่ตั้งค่าไว้ โดย agent ไม่ได้รับ secret ต้นฉบับไป
- Decision records: บันทึก policy decisions เป็น OTLP JSON โดย default ไปที่
<box_dir>/private/telemetry/records.jsonl - เรียกโปรแกรมอย่าง
gitหรือcargoหรือ local MCP server ได้ โดย Box ตรวจการ launch ตาม policy แล้วรันโปรแกรมนั้นใน sandbox ของตัวเอง
เหมาะกับใคร
เหมาะกับคนที่ปล่อย coding agent หรือ AI agent ให้รันงานจริงบนเครื่อง แล้วอยากมีขอบเขตการเข้าถึงที่ชัดเจนกว่าการปล่อยสิทธิ์เต็ม เช่น กำหนดว่าอ่านไฟล์ไหนได้ รันคำสั่งอะไรได้ ออกเน็ตไปทาง method และ path ไหนได้ และอยากให้ secret ไม่หลุดเข้า agent process
เหมาะกับทีมที่รัน agent หลายตัวและอยากได้ decision records ไว้ตรวจสอบย้อนหลัง เพราะมี log เป็น OTLP JSON ให้ดู
อย่างไรก็ตามตอนนี้รองรับแคบ คือ macOS บน Apple silicon ถ้าทำงานบน Linux หรือ Windows ยังใช้ไม่ได้
เริ่มต้นใช้งาน
คู่มือเริ่มต้นอยู่ที่ docs/user/getting-started.md และต้องมี Mac ที่ใช้ Apple silicon, macOS 15 ขึ้นไป, Node.js 22.21 ขึ้นไปจาก Homebrew และเข้าถึง Claude Opus 5 บน Amazon Bedrock ใน region us-west-2
สคริปต์ดาวน์โหลดจะเช็ค checksum ของ release และแตกไฟล์ไบนารีไว้ใน ./box-core โดยไม่แก้ PATH หรือ system directory
curl -fsSL https://raw.githubusercontent.com/strands-agents/box/main/download.sh | sh
./box-core/box --version
ต้องเก็บไฟล์ไบนารีที่ดาวน์โหลดมาไว้ด้วยกันใน ./box-core จากนั้นทำตามคู่มือเพื่อเขียน box.toml และ policy.dw แล้วรัน box
ถ้าต้องการ build จาก source ตัวโปรเจกต์เป็น Cargo workspace และ rust-toolchain.toml จะ pin compiler ไว้ โดย rustup จะติดตั้งให้ในการ build ครั้งแรก
git clone https://github.com/strands-agents/box.git
cd box
cargo build --release -p strands-box -p strands-box-containment
รันไบนารีที่ได้เป็น ./target/release/strands-box และเก็บ helper binaries ไว้ใน directory เดียวกัน
งานที่พบบ่อยรันผ่าน just
just build # the CLI, the alias image, and the containment trampoline
just test # workspace tests
just check # pre-push gate: fmt-check + clippy + test
just test-all # workspace tests and box example checks
ถ้าจะแก้ว่า box อนุญาตอะไรบ้าง ให้แก้ box.toml เพื่อเปลี่ยน environment และ direct access grants ของ agent และแก้ policy.dw เพื่อเปลี่ยน rule สำหรับ operation ที่ Box ตรวจผ่าน interpreters และ gateways
มีตัวอย่าง Python SDK ของ Strands อยู่ที่ examples/strands-box/strands-sdk-agent/ เป็น agent เล็กๆ ที่มีสาม tools ใช้ Shell ดูรายละเอียด dependency และวิธีรันได้ที่ examples/README.md
ข้อควรรู้
License: Apache License 2.0 เปิดใช้งานและดัดแปลงได้ตามเงื่อนไขของ Apache 2.0
ความสดใหม่: push ล่าสุดวันที่ 11 ต.ค. 2026 ตัวเลขดาว 312, fork 14, open issues 41 ณ ข้อมูลวันที่ 11 ต.ค. 2026 โปรเจกต์ยังไม่ถูก archive
อายุโปรเจกต์: สร้างเมื่อ 2 ต.ค. 2026 อายุราว 9 วัน ณ ข้อมูลวันที่ 11 ต.ค. 2026 ถือว่าใหม่มากและยังอยู่ในช่วง Preview
ข้อจำกัดที่ควรรู้:
- รองรับแคบ รองรับเฉพาะ macOS บน Apple silicon ส่วน Linux อยู่ในแผน ยังไม่รองรับเครื่อง Intel Mac
- ยังอยู่ในสถานะ Preview ตัว README บอกว่ารับ feedback ผ่าน GitHub issues และให้อ่าน CONTRIBUTING.md ก่อนส่ง PR
- direct filesystem grants ใน
box.tomlถูก OS บังคับใช้และจะไม่ผลิต Dogwood decision ราย operation ถ้าอยากให้ policy คุม file operations ต้องใช้ interpreters และเก็บไฟล์เหล่านั้นออกจาก direct grants ของ agent - policy ใช้ default-deny คือ operation ที่ผ่านการตรวจถูกปฏิเสธหากไม่มี
permitที่ตรงและถ้ามีforbidตรงกันจะ override permit ทิ้ง ต้องเขียน policy ให้ครบไม่งั้น agent จะทำงานไม่ได้ - มี opinionated requirements ใน getting started เช่น Node.js 22.21 ขึ้นไป และต้องเข้าถึง Claude Opus 5 บน Bedrock ใน us-west-2
- ตัว skill สำหรับช่วยเขียน policy ดึงมาจาก URL ภายนอก ควรอ่านทีละส่วนก่อนนำไปใช้กับ agent ของตัวเอง
- มี open issues อยู่ 41 รายการเหมาะกับคนที่พร้อมช่วยทดสอบและรายงานปัญหาในช่วง Preview
🔗 https://github.com/strands-agents/box
ข้อมูลจาก GitHub ณ 11 ต.ค. 2026: ⭐ 312 | ภาษา Rust | license Apache-2.0