First of all: this is NOT for folks who are already using a sandbox. The guarantees provided by Autobox are weaker. This is rather for folks who "hesitate" to use sandboxes.
Autobox is built around two observations I kept making over past one year of seeing sandbox launches and their real-world usage:
1. There are many sandboxing options now, and they work well. But leaving a handful few, almost nobody uses them. The blocker isn't the technology, it's the setup friction — however small it looks on paper, it's enough that people skip it entirely.
2. LLMs mostly don't write harmful code or take destructive steps. They're not adversarial by default.
Autobox bets on the second observation to remove the first. Instead of asking you to configure a sandbox, it's just there: every tool call carries its own permissions, and anything you don't explicitly allow is denied.
Is it perfect? No - seatbelt filesystem rules are best-effort, and the strong isolation is the V8 path.
Is it better than using no sandbox at all? Definitely yes.
This is also for M-series Macs only.
---
Oh, and the best part: "copy_then_sync":
Using APPFS `clonefile`, Autobox can hand your agent a full, "writable" copy of a repo instantly (1-2 ms). The agent gets something it can freely "destroy", but, your actual working tree is untouched. Your agent can then verify things, and of all looks okay, in one command sync the changes back to host within milliseconds.