h5i
Your AI coding agent can run out of control.
Permissions off, on your machine. It runs as you.
no box your real $HOME
It did exactly what you asked.
Everything you own was within reach.
credentials exfiltrated
on your real machine
h5i

h5i gives it a disposable box to run in.

The agent, the workspace, the shell, the dependencies, the dev server and a browser: one boundary.

📦 env/you/webapp · sealed
Your workspace, copied in
.git/.h5i/env/you/webapp/work
Claude Code · shell · toolchain · Chrome
all inside the same boundary
POLICY, PINNED AT CREATION
fs.write$WORK only
net.egressregistry.npmjs.org · api.anthropic.com
secretsnone enter the box
✋ fs
✋ net
BLOCKED BY POLICY
Full autonomy for the agent.
Nothing to lose for your machine.
terminal · youhost
Turn off the permission prompts. The box is the permission.
Want a harder wall? --isolation microvm boots a guest with its own kernel.

Watch the same browser. Take over anytime.

terminal · youhost
localhost:3000 · inside the box control: agent

Create your account

test@example.com
Sign up
✓ Account created
Your host browser never connects to the app. The box's Chrome does.

Nothing leaves without your review.

terminal · youhost
patch.diff · 9 files
report.md
signup.png
receipt.json
2 denials, listed
Like it? git apply the patch. Either way: h5i box rm webapp
Give your agent a whole machine.
Just not yours.
h5i
Auditable Sandbox for AI Coding Agents
h5i box · one command, one boundary
receipts · what actually ran
A denial is not a crash. The agent keeps going.
0:00