Sandcat: sandbox for securely running AI agents in “dangerous” mode

Sandcat is a Docker & dev container setup for securely running AI agents (Claude Code, Cursor CLI, Codex CLI, GitHub Copilot CLI). The environment is sandboxed, with controlled network access and transparent secret substitution — while retaining the convenience of working in an IDE — both VS Code and JetBrains are supported.

All container traffic is routed through a transparent mitmproxy via WireGuard, capturing HTTP/S, DNS, and all other TCP/UDP traffic without per-tool proxy configuration. A straightforward allow/deny-list engine controls which network requests go through, and a secret substitution system injects credentials at the proxy level so the container never sees real values.

Source code: github.com/VirtusLab/sandcat.

Note

Sandcat is part of Visdom, VirtusLab’s AI-native SDLC platform.

Installation

Commercial Support

We offer commercial services around AI-assisted software development. Contact us to learn more about our offer!