Sandcastle on a Mac
Orchestrate sandboxed coding agents (isolated containers) · Agent Platforms
Sandcastle runs AI coding agents inside isolated sandboxes — each agent gets its own Docker/Podman (or Vercel) container with full isolation, and commits made in the sandbox are patched back to the host automatically. Provider-agnostic (Claude Code, Codex, OpenCode…), local/offline, MIT-licensed; orchestrate runs in TypeScript with a single sandcastle.run(). A safe way to let agents execute untrusted code without touching your machine.
Run Sandcastle with FrontierStack
FrontierStack lists Sandcastle in its Agent Platforms catalog. Install or connect it from one place, then monitor its status, ports and certificate, secure it with the firewall and Malware Audit, and back it up.
Run it all from one Mac app.
FrontierStack installs, monitors and secures the whole stack — locally and across your fleet — from a single native macOS app.
Download FrontierStack