Compare
Is omabox what you need?
It does one thing: keep agents off your desktop while they test on a desktop of their own. If you want something else, these projects are good at it.
Your agents build and test GUI apps, plugins or themes on Omarchy, several at once
omabox
Parallel, invisible Omarchy desktops, up in about 4 s for about 500 MB each, and your own untouched. Omarchy on Linux only, and not a security boundary.
You want an agent on your own desktop, beside you, or cloud machines for agents at scale
Cua
Cua's fleets run computer-use agents on cloud Linux, Windows, macOS and Android machines for training and evals, and it now runs sandboxes on your own machine too. Its Driver works on your own macOS, Windows or Linux desktop, through a CLI, MCP or SDKs, and can click and type without taking your cursor or focus where the app allows it (on Hyprland, still experimental and a few apps). omabox does the opposite: it keeps agents off your desktop.
You want to limit what the agent itself can read, write and reach
ai-jail
A jail for the agent process, on Linux, macOS and Windows through WSL2: your home, SSH keys and cloud credentials out of reach, the project writable. omabox isn't a sandbox; ai-jail is one, and the two stack.
You need a whole machine: the real installer, system services, a reboot
omarchy-in-omarchy
A disposable Omarchy in QEMU/KVM, 8 GB of RAM by default. Heavier: it installs itself once, in about 30 minutes, then boots in about 18 seconds. A real machine, where a box has no system bus.
Checked on 2026-10-01 against each project's own site. They move on their own, so check theirs.
Better together
ai-jail fences the agent in. omabox keeps its windows out.
ai-jail, by Fabio Akita (AkitaOnRails), is the sandbox we point people to. It runs an agent inside bubblewrap, Landlock and seccomp on Linux (and Windows through WSL2), and sandbox-exec on macOS. It does carefully the one thing omabox doesn't do: limit what the agent can read, write and reach. The two answer different questions, so they stack.
- your project, at its real path
- ~/.ssh, ~/.aws, ~/.gnupg
- your shell's tokens
- network, unless you allow it
the box's
No window, no focus change, no prompt.
ai-jail answers: what can it touch?
A fence around the agent
- Your project read-write at its real path,
/usrread-only - A fresh home: no
~/.ssh,~/.aws,~/.gnupgor browser profiles - The environment cut to an allowlist, so tokens stay in your shell
- Network, display, GPU and Docker off until you allow them
omabox answers: where does it draw?
A desktop of its own
- Its own screen, pointer and keyboard
- Its own session bus, tray, notifications and keyring
- Your cursor, focus and workspaces untouched
- Not a security boundary: that part is ai-jail's
Try a build you don't trust yet
A contributor's branch, an app you just downloaded: run it in ai-jail, and give it the box's screen as its only display.
ai-jail keeps it out of your home, keys and network; its window opens in the box, where omabox shot and
peek see it.
$ omabox up $ eval "$(omabox env)" # Wayland clients now draw in the box $ ai-jail --gpu --rw-map "$WAYLAND_DISPLAY" --env WAYLAND_DISPLAY -- ./build/app
Tested with ai-jail 2.6.2 and omabox 0.4.3 on Linux.
Or jail the agent itself
A jail can't start a box on its own, so its omabox hands each command to a broker outside, with no
change to ai-jail. up, shot, keys, click and the rest work in the
jail as outside. The broker keeps a jail's boxes to what the jail has: no network when the jail has none, only its own
project, only the boxes it started, all gone when it exits.
$ omabox broker on # prints the lines to add to ~/.ai-jail $ ai-jail claude
Tested with ai-jail 2.2.1 and 2.6.2 and omabox 0.4.4 on Linux.
Not for a jailed agent: omabox host, peek, interactive boxes, the guard and
config changes. Driving a box is running code in it, so the broker is what keeps a box from being a way out
of the jail.
Keep reading
Each part, on its own page.
Install
Give every agent a desktop of its own.
Omarchy 4 with Hyprland 0.56 or later, and a GPU. Three minutes, then your agents take it from there.
$ git clone https://github.com/diogochaves/omabox && cd omabox && ./install.sh