Sand is a Swift CLI for creating small, named Linux environments on Apple silicon Macs. Each Sandbox VM has its own tools, shell state, package cache, and Pi login. The Host Mac only exposes folders you explicitly allow.

I built it because coding agents are useful enough that I want them to run real shell commands, but not useful enough to trust with my entire home folder. Sand gives them a little Linux box, persistent guest state, and a clear boundary around the project folders they can touch.

sand create box
sand folders add box ~/Projects/my-project rw --as /workspace
sand box run pi
sand box shell

How it works

The first backend uses Apple’s container CLI, but the rest of Sand talks in its own product language: Sandbox VM, Allowed Folder, Guest Path, Guest State, Sandbox Session, and Workload Command. The Apple-specific backend details sit behind a SandboxBackend interface so the messy part stays contained.

Links

GitHub repo
Documentation
Build notes / blog post

project, ai, tools, programming