BoxClaw SDK
Zero-Trust Runtime Execution Sandboxing for AI Agents
The boxclaw SDK acts as the execution-environment boundary for LLMs operating inside agent frameworks (like OpenClaw, LangChain, or custom OpenAI scripts). By wrapping standard Python operations in our native OS-Hooks (sys.addaudithook), any AI acting through the functions decorated with our @boxclaw_guardrail must provide mathematical or deterministic proof that its intended behavior adheres to local security invariants.
This is fundamentally different from semantic guardrails (which scan text output for bad words). BoxClaw catches real OS system calls, FFI loads (like ctypes), network requests, and filesystem writes at the CPython Virtual Machine level.
Installation
pip install boxclaw
Usage
Agent frameworks often grant LLMs unrestricted access to local system resources (e.g., executing arbitrary Bash commands or running generated Python scripts). BoxClaw allows you to restrict the AI to authorized capabilities only.
To set it up, simply wrap the function your Agent uses with the @boxclaw_guardrail and declare exactly what operations it is allowed to perform.
Example: Securing a File Agent
from boxclaw import boxclaw_guardrail
import subprocess
import os
# Limit the agent strictly to Network requests.
# It is completely blocked from modifying the File System or running Bash Commands.
@boxclaw_guardrail(agent_id="web-crawler-bot", required_capabilities=["network_send"])
def agent_execute(llm_generated_code: str):
# DANGEROUS! If the LLM generates malicious code here (e.g. `import os; os.system('rm -rf /')`),
# BoxClaw will instantly catch the deep OS call and throw a PermissionError Exception.
exec(llm_generated_code)
try:
# ❌ This will trigger the Sandbox Security Guard and throw an exception
# because the agent ONLY has network_send capabilities.
malicious_ai_action = "with open('stolen_data.txt', 'w') as f: f.write('secret')"
agent_execute(malicious_ai_action)
except Exception as e:
print(f"Blocked by BoxClaw: {e}")
Security Capabilities
You can specify specific scopes to limit your LLMs strictly to the tasks you hired them to do:
system_execute: Blocks arbitrary subprocess commandsnetwork_send: Blocks unauthorized HTTP/socket connectionswrite_fs: Prevents the agent from modifying the filesystemffi_load: Mathematically blocks C-Extensions /ctypessandbox escapes
Links
- PyPI Package: https://pypi.org/project/boxclaw/
- GitHub Repository: https://github.com/certior/boxclaw
Metadata
Release files for boxclaw 0.1.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| boxclaw-0.1.3.tar.gz | 12.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| boxclaw-0.1.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 27.5 kB
Release files / boxclaw-0.1.3.tar.gz
| Download URL | boxclaw-0.1.3.tar.gz |
|---|---|
| Size | 12.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0b18d16625421f2e7a218aaf9b9e5d47fc58205967035e1a74952d7755907cf5
|
|
BLAKE2b-256 checksum How to use checksums |
c32287a6fa1cd0e1467aeba9b5dfc7563b8eb66c8749dc7ce02701e75f6b41bc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.9
|
Release files / boxclaw-0.1.3-py3-none-any.whl
| Download URL | boxclaw-0.1.3-py3-none-any.whl |
|---|---|
| Size | 15.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
94741bf916a032cc5c087770d1903446247d2bff373684c0a1406cb3f4056b9d
|
|
BLAKE2b-256 checksum How to use checksums |
bf52bf2f00c7624be83ab5a52589ecadc128910f67add197eb47f20ffea8237c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.9
|