Announced 7 Oct 2026 · Sources checked
What did AWS ship on 7 October?
The Open Source Blog post is the announcement object: Strands Box enters developer preview as open source under Apache 2.0, building on earlier Dogwood language and Dogwood Local Engine releases. Marc Brooker’s companion “big picture” post on strandsagents.com situates Box inside AWS’s longer agent-safety investment line (AgentCore, policy, isolation).
GitHub’s strands-agents/box repository matches that story. The API record we opened lists Apache-2.0, description text about OS isolation plus default-deny Dogwood policies and credential injection, and release v0.1.0 published 7 October 2026 at 17:24:27 UTC. The README calls Box harness-agnostic: you pick the agent binary, configure access in box.toml, and write policy.dw.
File this beside other October sandboxing GA/preview notes such as GitHub Copilot local sandboxing—Copilot’s MXC path is product-integrated; Strands Box is an open engine you wrap around agents you choose.
How do containment and Dogwood policy split duties?
AWS’s post describes two layers. Containment uses OS-level isolation (macOS Seatbelt) to bound what the agent process can reach on disk and on the network. Policy then governs actions inside that boundary at enforcement points: network egress, a Python interpreter, a Shell interpreter, and an MCP broker.
Those enforcement points share an event history. A rule can allow Slack posts but cap them to three per ten minutes, or deny HTTP after a sensitive directory read—even if the read happened through Shell and the HTTP call through Python. Dogwood’s permit/forbid model is default-deny for engine-checked operations: a matching permit is required, and forbid wins.
The egress gateway terminates TLS for outbound traffic, asks policy about connections/requests, and can inject credentials so secrets never sit in the agent’s environment. Docs warn that tools or local MCP servers may set network.contain_egress = false; treat that flag as a deliberate hole.

What does the platform matrix allow today?
The Strands Box docs table we opened is blunt: macOS 15 or later on Apple silicon is supported; Linux is “not supported yet”; Windows is unsupported. The README’s preview line matches. If your agents run on Linux CI or Windows laptops, Box is not a drop-in control today.
AWS’s blog sketches a future where developers package agents with Box for Bedrock AgentCore, ECS, or Kubernetes so policies travel with the deployment. No dated GA for that path appears in the pages we opened. Keep “bring Box to deployed agents” in the roadmap column.
Pre-release software notes on the docs site matter operationally: 0.1.x configuration keys, policy actions, and CLI flags can change; pin BOX_VERSION when downloading and read release notes before upgrading.
How should teams trial Box without theatre?
Start with a disposable project directory and a policy that permits fs:read/write only under that tree, forbids `.env`, and allows a narrow egress allowlist. Run a hostile prompt that tries to read `~/.ssh` and to POST a secret to an external host. Expect deny decisions in Box’s logs if Seatbelt and Dogwood are wired as documented.
Compare enforcement points with NVIDIA OpenShell’s runtime controls and with product sandboxes you already pay for. Overlapping vocabulary (“policy”, “sandbox”) does not mean interchangeable guarantees.
If you use MCP servers, decide which run inside the broker’s policy path and which set contain_egress=false. Document that matrix beside your agent runbooks; a single “we use Strands Box” slide hides those exceptions.
- Pin v0.1.0 or a later tag; record the commit SHA beside the trial.
- Write a forbid for secrets paths before the first permit for project write.
- Attempt denied egress and confirm the gateway, not the model, stopped it.
- Retest after any BOX_VERSION bump—preview flags move.

Where does Box sit against other October sandboxes?
Copilot’s local sandboxing GA is a product toggle for GitHub’s agent hosts. OpenShell is NVIDIA’s runtime-control narrative. Strands Box is an open engine: you bring the agent binary, you own box.toml and policy.dw, and you accept an Apple-silicon-only preview matrix. Those are complementary layers, not substitutes.
Dogwood’s history-aware rules are the distinctive bet. If your threat model is “the agent already read payroll.csv, so deny egress for ten minutes,” you need shared event history across tools—something a pure Seatbelt profile does not express. If your threat model is only “never leave /src/project,” containment grants may be enough and Box’s policy language is optional complexity.
For the broader isolation vocabulary—process boundaries, approval gates, and review—see our AI agent sandboxing explainer.
What did we not verify?
We did not download the Box binary, run `box run`, execute Seatbelt profiles, or evaluate Dogwood policies on a Mac. Platform support, Apache-2.0 licensing, and architectural claims are taken from the AWS blog, Strands docs, README, and GitHub API/release JSON we opened and hashed on 10 October 2026. Performance and breakout resistance are untested here.
Common questions
Does Strands Box run on Linux today?
Not according to the docs table we opened on 10 October 2026. Supported hosts are macOS 15+ on Apple silicon; Linux is listed as not supported yet.
Is Dogwood required?
Box embeds the Dogwood Local Engine and expects policy.dw rules for engine-checked actions. Containment still uses box.toml / Seatbelt grants.
Is this generally available?
No. AWS calls it developer preview; the GitHub release we saw is v0.1.0.
What to remember
Strands Box is AWS’s 7 October Apache-2.0 developer-preview sandbox for Apple-silicon Macs—Seatbelt for reach, Dogwood for history-aware allow/deny. Trial it where the matrix fits; do not invent Linux support.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





