Compare

Is omabox what you need?

It does one thing: keep agents off your desktop while they test on a desktop of their own. If you want something else, these projects are good at it.

Your agents build and test GUI apps, plugins or themes on Omarchy, several at once

omabox

Parallel, invisible Omarchy desktops, up in about 4 s for about 500 MB each, and your own untouched. Omarchy on Linux only, and not a security boundary.

You want an agent on your own desktop, beside you, or cloud machines for agents at scale

Cua

Cua's fleets run computer-use agents on cloud Linux, Windows, macOS and Android machines for training and evals, and it now runs sandboxes on your own machine too. Its Driver works on your own macOS, Windows or Linux desktop, through a CLI, MCP or SDKs, and can click and type without taking your cursor or focus where the app allows it (on Hyprland, still experimental and a few apps). omabox does the opposite: it keeps agents off your desktop.

You want to limit what the agent itself can read, write and reach

ai-jail

A jail for the agent process, on Linux, macOS and Windows through WSL2: your home, SSH keys and cloud credentials out of reach, the project writable. omabox isn't a sandbox; ai-jail is one, and the two stack.

You need a whole machine: the real installer, system services, a reboot

omarchy-in-omarchy

A disposable Omarchy in QEMU/KVM, 8 GB of RAM by default. Heavier: it installs itself once, in about 30 minutes, then boots in about 18 seconds. A real machine, where a box has no system bus.

Checked on 2026-10-01 against each project's own site. They move on their own, so check theirs.

Better together

ai-jail fences the agent in. omabox keeps its windows out.

ai-jail, by Fabio Akita (AkitaOnRails), is the sandbox we point people to. It runs an agent inside bubblewrap, Landlock and seccomp on Linux (and Windows through WSL2), and sandbox-exec on macOS. It does carefully the one thing omabox doesn't do: limit what the agent can read, write and reach. The two answer different questions, so they stack.

ai-jail · the fence./build/app
  • your project, at its real path
  • ~/.ssh, ~/.aws, ~/.gnupg
  • your shell's tokens
  • network, unless you allow it
one Wayland socket:
the box's
omabox · its screen
./build/appdrawn in the box
Your desktop

No window, no focus change, no prompt.

ai-jail answers: what can it touch?

A fence around the agent

  • Your project read-write at its real path, /usr read-only
  • A fresh home: no ~/.ssh, ~/.aws, ~/.gnupg or browser profiles
  • The environment cut to an allowlist, so tokens stay in your shell
  • Network, display, GPU and Docker off until you allow them

omabox answers: where does it draw?

A desktop of its own

  • Its own screen, pointer and keyboard
  • Its own session bus, tray, notifications and keyring
  • Your cursor, focus and workspaces untouched
  • Not a security boundary: that part is ai-jail's

Try a build you don't trust yet

A contributor's branch, an app you just downloaded: run it in ai-jail, and give it the box's screen as its only display. ai-jail keeps it out of your home, keys and network; its window opens in the box, where omabox shot and peek see it.

$ omabox up
$ eval "$(omabox env)"   # Wayland clients now draw in the box
$ ai-jail --gpu --rw-map "$WAYLAND_DISPLAY" --env WAYLAND_DISPLAY -- ./build/app

Tested with ai-jail 2.6.2 and omabox 0.4.3 on Linux.

Or jail the agent itself

A jail can't start a box on its own, so its omabox hands each command to a broker outside, with no change to ai-jail. up, shot, keys, click and the rest work in the jail as outside. The broker keeps a jail's boxes to what the jail has: no network when the jail has none, only its own project, only the boxes it started, all gone when it exits.

$ omabox broker on   # prints the lines to add to ~/.ai-jail
$ ai-jail claude

Tested with ai-jail 2.2.1 and 2.6.2 and omabox 0.4.4 on Linux.

Not for a jailed agent: omabox host, peek, interactive boxes, the guard and config changes. Driving a box is running code in it, so the broker is what keeps a box from being a way out of the jail.

Keep reading

Each part, on its own page.

Install

Give every agent a desktop of its own.

Omarchy 4 with Hyprland 0.56 or later, and a GPU. Three minutes, then your agents take it from there.

$ git clone https://github.com/diogochaves/omabox && cd omabox && ./install.sh