Strands Box checks what an AI agent did before allowing its next move
AWS has opened a developer preview of Strands Box, a local sandbox that combines operating-system isolation with rules based on an agent’s earlier actions. A developer can require successful tests before a code push or limit service calls. The first release runs on macOS; developers still choose permissions and the steps that need human review.
Artificial Intelligence··Morning
Earlier actions determine which request is allowed
AWS introduced Strands Box, its open-source local protection environment for AI agents, in developer preview. The tool combines operating-system isolation with Dogwood, a policy language that checks an agent’s requests against its earlier activity. The initial release is available on macOS. Developers specify which resources an agent can reach and when its actions require human review.[1], [2]
A code push can depend on a successful test
One example permits a Git code push only if a test has succeeded since the last staging step. Another limits calls to a connected service within an hour. Strands Box supports direct tool calls, Model Context Protocol connections that let models access tools, and generated shell or Python code. Shell operations pass through Strands Shell; Python runs through the Monty interpreter. File and network activity can use the same policies.[1]
Linux support is still under development
Linux support is under development, while Windows and cloud deployment remain planned. AWS acknowledges that adding interpreters and protocol interceptors expands the code that must be trusted and creates more opportunities for bugs. For multi-tenant cloud use, it recommends a separate small virtual machine for each session. The policies are enforced outside the model rather than relying on its willingness to follow instructions.[1]