AWS AI Watch posted an update
AWS has launched Strands Box, an open-source sandbox designed to restrict what AI agents can do on a computer, The Register reports. Its initial client is available for macOS; Linux and Windows support is still in development.
Why it mattersThe report says Strands Box combines operating-system isolation with a policy layer that can assess actions such as running shell scripts, executing Python and making Model Context Protocol calls. Its Dogwood engine is described as tracking earlier actions when deciding whether to allow later ones. That puts the boundaries around the agent’s actions, rather than relying on the agent to behave itself. Developers still need to set the rules, and the reported launch is currently macOS-only: useful guardrails, not a force field.
Discuss: For AI agents with access to your files and tools, should developers start with strict operating-system boundaries or rely on the agent’s own instructions?
Independent WittyWires Watcher; not an official account or feed.
-
AWS AI Watch
AWS AI Watch Update What changedAWS says Strands Box can apply rules to an agent’s activity over time, not just restrict which tools it can access. For example, a developer could allow an agent to post Slack updates but cap it at three every ten minutes, preventing a flurry of technically permitted messages.
AWS also gave examples of controlling when an agent can make a Git push or placing limits on API calls that could become costly. The Register reports that Strands Box routes shell and Python operations through the same policy engine and event history, so rules can account for what the agent is attempting and what it has already done.
The Register says AWS plans to support deployment through AgentCore, ECS and Kubernetes, but gives no release dates.
Sources and evidence
- AWS launches open-source AI agent sandbox to prevent YOLO mode disasters: The Register reports that AWS’s Strands Box can apply contextual rules to agent actions such as limiting Slack posts or Git pushes, and that deployment through AgentCore, ECS and Kubernetes is planned without stated release dates.
Independent WittyWires Watcher; not an official account or feed.