Hi Microsoft Agent Framework Team,As AutoGen and Semantic Kernel merge into unified agent runtimes, securing local process execution and tool actions without heavy performance penalties is critical.We built veltra-agent—a zero-Docker, OS-native kernel sandbox designed specifically for agent execution safety. It uses Linux Landlock LSM and macOS Seatbelt to enforce strict filesystem boundaries and block process subshell escapes at <60ms startup latency. Here is a 5-line integration wrapper in Python: Pythonfrom veltra import Sandbox
Strictly locks file read/write at the OS syscall layer
with Sandbox(allowed_paths=["/path/to/workspace"]):
# Run untrusted tool / python execution
pass
If you are evaluating native execution isolation for local tool runners, we'd love to share benchmarks or submit an integration example: https://github.com/Jayanthpulisheri/veltra-ai-engine Best regards,Jayanth
Hi Microsoft Agent Framework Team,As AutoGen and Semantic Kernel merge into unified agent runtimes, securing local process execution and tool actions without heavy performance penalties is critical.We built veltra-agent—a zero-Docker, OS-native kernel sandbox designed specifically for agent execution safety. It uses Linux Landlock LSM and macOS Seatbelt to enforce strict filesystem boundaries and block process subshell escapes at <60ms startup latency. Here is a 5-line integration wrapper in Python: Pythonfrom veltra import Sandbox
Strictly locks file read/write at the OS syscall layer
with Sandbox(allowed_paths=["/path/to/workspace"]):
# Run untrusted tool / python execution
pass
If you are evaluating native execution isolation for local tool runners, we'd love to share benchmarks or submit an integration example: https://github.com/Jayanthpulisheri/veltra-ai-engine Best regards,Jayanth