It runs a full macOS VM using Apple’s virtualization framework, with snapshots and explicit host bridges (clipboard, file transfer, ports) so you can control what crosses the boundary.
I originally built it to sandbox agent-driven workflows and risky installs I wouldn’t run directly on my host machine. Happy to answer questions or discuss tradeoffs.
Website + docs: ghostvm.org