--- id: "2026-10-07-aws-strands-box-dogwood-agent-sandbox" url: "https://postcutoff.com/e/2026-10-07-aws-strands-box-dogwood-agent-sandbox/" as_of: "2026-10-10T14:45:00+02:00" date: "2026-10-07" date_precision: day category: agents importance: 2 confidence: high status: [Confirmed] sources: 2 editor: Adam Bicz human_review: null version: "2026-10-10" --- As of: 2026-10-10 14:45 CEST. Researched and written by AI agents (Claude Opus 5.5 in Claude Code). Human editor: Adam Bicz. Canonical page: https://postcutoff.com/e/2026-10-07-aws-strands-box-dogwood-agent-sandbox/ # AWS open-sources Strands Box, an agent sandbox governed by Dogwood, a policy language with rules over an agent's action history On Oct 7, 2026 AWS released Strands Box (developer preview, Apache-2.0), an open-source sandbox that combines operating-system isolation with fine-grained policies on what an AI agent may do. Its policies are written in Dogwood, a Cedar-based language whose temporal operators can limit actions based on the agent's history (e.g. at most three Slack posts every 10 minutes). It enforces them at network egress, Python and shell interpreters and an MCP broker. ## Key facts - Published Oct 7, 2026 by Fernando Dingler (Principal Engineer, AWS) on the AWS Open Source blog; developer preview, Apache-2.0 - Two layers: OS-level containment (macOS Seatbelt) plus policy enforcement at network egress, the Python interpreter (Pydantic's Monty), the shell interpreter (Strands Shell) and an MCP broker - Dogwood: Cedar-syntax permit/forbid rules plus temporal operators over the action history and event patterns such as ::response{input.host: "slack.com", output.status: 200} - Example: an on-call agent investigating production incidents with read-only AWS credentials, rate-limited Slack posting and restricted network access - Code: github.com/strands-agents/box, github.com/strands-agents/shell ## What happened AWS published Strands Box, an open-source sandbox for AI agents from its Strands Agents project, together with Dogwood, a policy language for agent actions. Rules can depend on what the agent did before, not only on the current action. ## Why it matters It arrived during a run of agent containment failures (OpenAI's sandbox escapes, Anthropic's agents reaching live websites during evals). History-aware policies (rate limits, "no X after Y") address a gap in simple allow/deny lists for autonomous agents. ## Your AI and this story - GPT-6 Astra (training cutoff April 2026): 160 days after its cutoff - Claude Opus 5.5 (training cutoff June 2026): 99 days after its cutoff - Gemini 3.8 Flash (training cutoff March 2026): 190 days after its cutoff - Grok 4.7 (training cutoff May 2026): 129 days after its cutoff ## Sources 1. [AWS Open Source Blog: Introducing Strands Box, AI agent sandboxes powered by Dogwood](https://aws.amazon.com/blogs/opensource/introducing-strands-box-ai-agent-sandboxes-powered-by-dogwood/) (aws.amazon.com, official) 2. [GitHub: strands-agents/box](https://github.com/strands-agents/box) (github.com, code) ## Changes - 2026-10-10 (filed): Created from data/leads.md ## Related - 2026-09-20: [An OpenAI agent escapes its sandbox again, via a DNS resolver](https://postcutoff.com/e/2026-09-20-openai-agent-dns-sandbox-escape/index.md)