Skip to main content

BoxClaw SDK

PyPI version License: MIT

Zero-Trust Runtime Execution Sandboxing for AI Agents

The boxclaw SDK acts as the execution-environment boundary for LLMs operating inside agent frameworks (like OpenClaw, LangChain, or custom OpenAI scripts). By wrapping standard Python operations in our native OS-Hooks (sys.addaudithook), any AI acting through the functions decorated with our @boxclaw_guardrail must provide mathematical or deterministic proof that its intended behavior adheres to local security invariants.

This is fundamentally different from semantic guardrails (which scan text output for bad words). BoxClaw catches real OS system calls, FFI loads (like ctypes), network requests, and filesystem writes at the CPython Virtual Machine level.

Installation

pip install boxclaw

Usage

Agent frameworks often grant LLMs unrestricted access to local system resources (e.g., executing arbitrary Bash commands or running generated Python scripts). BoxClaw allows you to restrict the AI to authorized capabilities only.

To set it up, simply wrap the function your Agent uses with the @boxclaw_guardrail and declare exactly what operations it is allowed to perform.

Example: Securing a File Agent

from boxclaw import boxclaw_guardrail
import subprocess
import os

# Limit the agent strictly to Network requests.
# It is completely blocked from modifying the File System or running Bash Commands.
@boxclaw_guardrail(agent_id="web-crawler-bot", required_capabilities=["network_send"])
def agent_execute(llm_generated_code: str):
    # DANGEROUS! If the LLM generates malicious code here (e.g. `import os; os.system('rm -rf /')`),
    # BoxClaw will instantly catch the deep OS call and throw a PermissionError Exception.
    exec(llm_generated_code)

try:
    # ❌ This will trigger the Sandbox Security Guard and throw an exception
    # because the agent ONLY has network_send capabilities.
    malicious_ai_action = "with open('stolen_data.txt', 'w') as f: f.write('secret')"
    agent_execute(malicious_ai_action)
except Exception as e:
    print(f"Blocked by BoxClaw: {e}")

Security Capabilities

You can specify specific scopes to limit your LLMs strictly to the tasks you hired them to do:

  • system_execute: Blocks arbitrary subprocess commands
  • network_send: Blocks unauthorized HTTP/socket connections
  • write_fs: Prevents the agent from modifying the filesystem
  • ffi_load: Mathematically blocks C-Extensions / ctypes sandbox escapes

Metadata

Release files for boxclaw 0.1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for boxclaw 0.1.3
File Size Uploaded
boxclaw-0.1.3.tar.gz 12.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for boxclaw 0.1.3
File Interpreter ABI Platform
boxclaw-0.1.3-py3-none-any.whl Python 3 none any Details

Total release size: 27.5 kB

Release files / boxclaw-0.1.3.tar.gz

Download URL boxclaw-0.1.3.tar.gz
Size 12.5 kB
Tags Source
SHA-256 checksum
How to use checksums
0b18d16625421f2e7a218aaf9b9e5d47fc58205967035e1a74952d7755907cf5
BLAKE2b-256 checksum
How to use checksums
c32287a6fa1cd0e1467aeba9b5dfc7563b8eb66c8749dc7ce02701e75f6b41bc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.9

Release files / boxclaw-0.1.3-py3-none-any.whl

Download URL boxclaw-0.1.3-py3-none-any.whl
Size 15.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
94741bf916a032cc5c087770d1903446247d2bff373684c0a1406cb3f4056b9d
BLAKE2b-256 checksum
How to use checksums
bf52bf2f00c7624be83ab5a52589ecadc128910f67add197eb47f20ffea8237c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.9

Release history Release notifications | RSS feed

This release

0.1.3 This release

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page