by boxlite-ai
The micro-VM for AI agents — light enough to embed on your laptop, elastic enough to power an agentic cloud.
# Add to your Claude Code skills
git clone https://github.com/boxlite-ai/boxliteLast scanned: 5/14/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-14T06:46:16.567Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how boxlite compares with popular alternatives.
boxlite is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by boxlite-ai. The micro-VM for AI agents — light enough to embed on your laptop, elastic enough to power an agentic cloud. It has 2,348 GitHub stars.
Yes. boxlite passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/boxlite-ai/boxlite" and add it to your Claude Code skills directory (see the Installation section above).
boxlite is primarily written in TypeScript. It is open-source under boxlite-ai on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh boxlite against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
BoxLite runs isolated applications in lightweight virtual machines, locally or through a cloud control plane.
A Box is a hardware-isolated micro-VM that runs any OCI image — and it persists. Agents install packages, write files, and resume across turns, never from cold.
Why BoxLite
python:slim, node:alpine, …).allow_net; inject real secrets via placeholders.One engine. Embed it, run it, deploy it, distribute it.
Import BoxLite and give your agent an isolated VM to run code — no daemon, no binary. (Python 3.10+)
pip install boxlite
import asyncio
import boxlite
async def main():
async with boxlite.SimpleBox(image="python:slim") as box:
result = await box.exec("python", "-c", "print('Hello from BoxLite!')")
print(result.stdout)
asyncio.run(main())
Node.js (npm install @boxlite-ai/boxlite, Node 18+)
import { SimpleBox } from '@boxlite-ai/boxlite';
const box = new SimpleBox({ image: 'python:slim' });
try {
const result = await box.exec('python', '-c', "print('Hello from BoxLite!')");
console.log(result.stdout);
} finally {
await box.stop();
}
Go (go get github.com/boxlite-ai/boxlite/sdks/go, Go 1.24+ with CGO)
ctx := context.Background()
rt, _ := boxlite.NewRuntime()
defer rt.Close()
box, _ := rt.Create(ctx, "alpine:latest")
defer box.Close()
result, _ := box.Exec(ctx, "echo", "Hello from BoxLite!")
fmt.Print(result.Stdout)
Rust (cargo add boxlite tokio futures --features tokio/macros,tokio/rt-multi-thread)
let runtime = BoxliteRuntime::default_runtime();
let litebox = runtime.create(BoxOptions {
rootfs: RootfsSpec::Image("alpine:latest".into()),
..Default::default()
}, None).await?;
let mut execution = litebox.exec(BoxCommand::new("echo").arg("Hello from BoxLite!")).await?;
let mut stdout = execution.stdout().unwrap();
while let Some(line) = stdout.next().await { println!("{}", line); }
Full runnable versions: Python, Node, Go, Rust, C.
No code needed — one install, then run any OCI image from your terminal.
curl -fsSL https://sh.boxlite.ai | sh
boxlite run python:slim python -c "print('Hello from BoxLite!')"
Installs to $HOME/.local/bin/boxlite, runtime embedded — no extra setup. Alternatives (cargo install boxlite-cli, version pinning, verification) → CLI reference.
boxlite serve
# Listening on 0.0.0.0:8100
curl -s -X POST http://localhost:8100/v1/boxes \
-H 'Content-Type: application/json' \
-d '{"image": "alpine:latest"}'
REST-capable CLI commands also work against a running server with --url:
boxlite --url http://localhost:8100 list.
Start with the architecture graphs, then follow the deployment guide for stage configuration, bootstrap, preview and verification. Choose the AWS guide or GCP guide for provider-specific setup, operations and costs. Neither cloud is preferred; the stage declaration selects the provider.
| Area | Capabilities |
|---|---|
| Execution | run any OCI image · async exec with streamed stdout/stderr + exit codes · interactive PTY with live resize · per-command timeout, workdir, env, run-as-user · entrypoint/cmd override |
| Isolation & security | a hardware-virtualized VM per box (KVM / Hypervisor.framework) · OS sandbox (seccomp / sandbox-exec) · CPU, memory & resource limits · egress allow-list (allow_net) · secret injection — real values never enter the VM · env sanitization |
| Storage & state | persists across stop/restart · volume mounts (ro/rw) · per-box QCOW2 disk with copy-on-write · bidirectional file copy · clone, or export/import as .boxlite archives · detached boxes that outlive the parent process |
| Networking | outbound internet · local TCP port forwarding · portable local/remote tunnels · network I/O metrics |
| Images | pull + cache any OCI image · custom & private registries · custom rootfs |
| Observability | per-box & runtime metrics — CPU, memory, network, boot time, commands · console logs · live stats |
| Interfaces | Python · Node.js · Go · Rust · C SDKs · the boxlite CLI · a REST API (WebSocket exec, optional auth) |
Agent frameworks run on BoxLite:
CONTAINER_DEPLOYMENT=boxlite)How BoxLite embeds a runtime and runs OCI containers inside micro-VMs. Details → Concepts.
┌──────────────────────────────────────────────────────────────┐
│ Your Application │
│ ┌───────────────────────────────────────────────────────┐ │
│ │ BoxLite Runtime (embedded library) │ │
│ │ │ │
│ │ ╔════════════════════════════════════════════════╗ │ │
│ │ ║ Jailer (OS-level sandbox) ║ │ │
│ │ ║ ┌──────────┐ ┌──────────┐ ┌──────────┐ ║ │ │
│ │ ║ │ Box A │ │ Box B │ │ Box C │ ║ │ │
│ │ ║ │ (VM+Shim)│ │ (VM+Shim)│ │ (VM+Shim)│ ║ │ │
│ │ ║ │┌────────┐│ │┌────────┐│ │┌────────┐│ ║ │ │
│ │ ║ ││Container││ ││Container││ ││Container││ ║ │ │
│ │ ║ │└────────┘│ │└────────┘│ │└────────┘│ ║ │ │
│ │ ║ └──────────┘ └──────────┘ └──────────┘ ║ │ │
│ │ ╚════════════════════════════════════════════════╝ │ │
│ └───────────────────────────────────────────────────────┘ │
└──────────────────────────────────────────────────────────────┘
│
Hardware Virtualization + OS Sandboxing
(KVM/Hypervisor.framework + seccomp/sandbox-exec)
Security Layers:
boxlite CLI reference, and the REST API contract (openapi/box.openapi.yaml)| Platform | Architecture | Status |
|---|