code-on-incus
Give the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops threats automatically.
为每个AI智能体提供独立的机器,具有root、Docker和systemd权限。主动防御自动检测并阻止威胁。
How to install
git clone https://github.com/mensfeld/code-on-incus ~/.claude/skills/code-on-incus About
code-on-incus (coi) **Isolated machines for AI coding agents - with active defense.** COI gives each AI agent its own machine - a full system container with root access, systemd, Docker, and the ability to install anything. Agents work like they would on a real server: run services, manage packages, use cron - without touching your actual system. Files stay correctly owned, no permission hacks needed. Your credentials stay on the host. SSH keys, environment variables, and Git tokens are never exposed to AI tools unless you explicitly mount them. If something goes wrong, COI catches it - revers…
Recommendation signals
Meta
- License
- MIT
- Language
- Go
- GitHub stars
- 728
- mo. downloads
- –
- Last push
- 2026-09-24
- Created
- 2026-01-07
Links
Basic safety check
- Findings
- curated 收录但无 npm 包/安装命令
- Sources
- curated:hesreallyhim/awesome-claude-code
- Topics
- agentic-ai, ai-tools, anthropic, claude, claude-code, code-sandbox, codex, coding-assistant, container-security, containers, developer-tools, incus, llm-security, llm-tools, lxc, opencode, opencode-ai, sandbox, sandboxing-tool, security
Related plugins
langfuse
langfuse/langfuse
🪢 Open source agent evals & observability: Trace, evaluate, and improve LLM applications with one open platform.
claude-code-templates
davila7/claude-code-templates
CLI tool for configuring and monitoring Claude Code
semiotic
nteract/semiotic
React data visualization library for streaming, networks, and AI-assisted development
dsh-desktop
dataelement/dsh-desktop
DSHDesktop:DeepSeek Harness Desktop / DeepSeek Harness 桌面版