Kontext applies identity-aware policy to AI agent actions.
Sandy contains AI coding agents with native macOS and Linux sandboxing.
AI agents can chain individually permitted operations into outcomes nobody intended.
Kontext gives agents a runtime identity, evaluates supported tool calls against policy, and blocks disallowed actions before they reach protected systems. Every decision produces evidence showing what the agent attempted, which policy applied, and why the action was allowed or denied.
brew install kontext-security/tap/kontextSandy confines AI coding agents to explicitly permitted files, network destinations, and processes using native operating-system sandboxing on macOS and Linux.
brew install kontext-security/tap/sandy| Layer | Question it answers | Project |
|---|---|---|
| Runtime authorization | Should this supported agent action proceed under policy? | Kontext |
| Process containment | What can this agent process access on the machine? | Sandy for macOS and Linux |
Use them independently or together for defense in depth.
| Repository | Description |
|---|---|
| kontext | Identity-aware runtime policy enforcement for AI agents |
| sandy | Native process containment for AI coding agents on macOS and Linux |
| agent-skills | Skills and integrations for using Kontext with AI agents |
- Explore the documentation
- Join the Discord community
- Follow Kontext Security on X