navikt/cplt
126 stars · Last commit 2026-10-04
Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level sandbox, with git and gh guards and sandbox policy committed to the repository.
README preview
# cplt [](https://github.com/navikt/cplt/actions/workflows/ci.yaml) [](https://github.com/navikt/cplt/actions/workflows/release.yaml) [](LICENSE)   **Kernel-enforced sandbox for AI coding agents.** cplt wraps GitHub Copilot CLI, OpenCode, Gemini CLI, Antigravity CLI, Pi, Claude Code, goose, DeepSeek Harness, or any shell, so the agent can write code but cannot steal credentials, push to main, merge PRs, or exfiltrate secrets. - **macOS**: Apple Seatbelt/SBPL via `sandbox-exec` - **Linux**: Landlock LSM + seccomp-BPF + optional Bubblewrap namespace isolation (kernel 5.13+, full network filtering on 6.7+) - **Windows**: no native support. There is no Windows sandbox backend. Run cplt inside WSL2, where it is an ordinary Linux install and the Microsoft kernel ships Landlock. See [Windows (WSL2) setup](#windows-wsl2).  ## Why cplt? AI agents execute arbitrary code. A compromised agent, whether through prompt injection, a supply chain attack, or a malicious MCP server, can read `~/.ssh`, push to main, merge PRs, or exfiltrate your code, unless the OS itself says no.