{
  "$schema_doc": "https://gtmstacker.com/registry/schema/entry.schema.json",
  "stability": "emerging",
  "generator": "agentic-media-registry",
  "generated_at": "2026-09-28T00:00:00Z",
  "id": "com.gtmstacker.registry/tool/kern-sandbox",
  "type": "tool",
  "slug": "kern-sandbox",
  "canonical_url": "https://gtmstacker.com/registry/tool/kern-sandbox/",
  "title": "Kern Sandbox",
  "description": "Kern Sandbox is a rootless, daemonless container runtime that runs LLM-generated code and agent tool calls in kernel-enforced isolation, callable from a CLI or Python/Node SDKs with MCP support. Open source: yes (Apache-2.0); self-hostable; pricing free. Single static binary; 427 stars; active.",
  "category": "ai-infrastructure",
  "tags": [
    "ai-infrastructure",
    "agent-sandbox",
    "code-execution",
    "isolation",
    "mcp-agents",
    "self-hostable"
  ],
  "status": "active",
  "revision": 1,
  "content_hash": "e12b192f7bbaa7691248c11650813fc85f6dc3f9fad36dc26c1d86aab0924fda",
  "date_published": "2026-09-28T00:00:00Z",
  "date_modified": "2026-09-28T00:00:00Z",
  "source": {
    "name": "getkern · GitHub",
    "url": "https://github.com/getkern/kern"
  },
  "license": "Apache-2.0",
  "one_liner": "Kern Sandbox runs LLM-generated code and agent tool calls rootless and daemonless, in kernel-enforced isolation, from a CLI or Python/Node SDKs.",
  "open_source": "yes",
  "self_hostable": "yes",
  "pricing_model": "free",
  "who_its_for": "An engineer running untrusted, LLM-generated code or agent tool calls who wants a fast, rootless, daemonless sandbox — no Docker daemon to run or privilege to grant — driven from a CLI or embedded via Python/Node SDKs, with MCP support to hand it to an agent directly.",
  "who_its_not_for": "Teams that need a managed, hosted execution service with an SLA rather than a self-run binary, or workloads that require full VM-level isolation beyond kernel-enforced containment.",
  "aliases": [
    "kern-sandbox",
    "kern",
    "getkern/kern",
    "kern sandbox"
  ],
  "alternatives": [
    "opensandbox",
    "boxhaven",
    "docker-sandbox-kit-spec"
  ],
  "secondary_categories": [
    "mcp-agents"
  ],
  "last_verified": "2026-09-28",
  "evidence": {
    "claim_type": "vendor-claim",
    "source_id": "https://github.com/getkern/kern",
    "note": "Apache-2.0 per repo; 427 stars; ships as a single static binary plus Python and Node SDKs, no daemon; rootless, kernel-enforced isolation; MCP support. Vendor-reported performance: ~1/20th the per-tool-call cost of `docker run`, 21x faster via a prewarm pool, and 7x faster than Docker on library imports (getkern.dev guide + repo, verified 2026-09-28)."
  },
  "caveats": "Verified from the primary repo and getkern.dev docs (2026-09-28); no independent testing here. The cost/speed figures (~1/20th `docker run` cost per call, 21x prewarm speedup, 7x faster imports) are the vendor's own benchmarks (vendor-claim), not independently reproduced — measure against your own workload. Kernel-enforced isolation is a container boundary, not a VM; threat-model accordingly for fully hostile code.",
  "lead": "Kern Sandbox is a rootless, daemonless container runtime that runs LLM-generated code and agent tool calls in kernel-enforced isolation, callable from a CLI or Python/Node SDKs with MCP support. Open source: yes (Apache-2.0); self-hostable; pricing free. It ships as a single static binary and has 427 stars.",
  "chunks": [
    {
      "index": 0,
      "heading_path": [],
      "est_tokens": 77,
      "text": "Kern Sandbox is a rootless, daemonless container runtime that runs LLM-generated code and agent tool calls in kernel-enforced isolation, callable from a CLI or Python/Node SDKs with MCP support. Open source: yes (Apache-2.0); self-hostable; pricing free. It ships as a single static binary and has 427 stars."
    },
    {
      "index": 1,
      "heading_path": [
        null,
        "What it does"
      ],
      "est_tokens": 229,
      "text": "Kern Sandbox is a rootless, daemonless container runtime that runs LLM-generated code and agent tool calls in kernel-enforced isolation, callable from a CLI or Python/Node SDKs with MCP support. Open source: yes (Apache-2.0); self-hostable; pricing free. It ships as a single static binary and has 427 stars.\n\nKern Sandbox gives an agent somewhere safe and fast to run code. It executes LLM-generated code and tool calls inside a container isolated by the kernel, but without a root requirement and without a background daemon — the whole thing is a single static binary you drop in and call. You reach it from a CLI, embed it through the Python or Node SDK, or expose it to an agent over MCP. The design target is throughput at agent scale: a prewarm pool keeps ready sandboxes on hand so a tool call does not pay full container-startup cost each time. Open source: yes (Apache-2.0); self-hostable; pricing free."
    },
    {
      "index": 2,
      "heading_path": [
        null,
        "Provenance"
      ],
      "est_tokens": 218,
      "text": "it through the Python or Node SDK, or expose it to an agent over MCP. The design target is throughput at agent scale: a prewarm pool keeps ready sandboxes on hand so a tool call does not pay full container-startup cost each time. Open source: yes (Apache-2.0); self-hostable; pricing free.\n\n- Apache-2.0 per repo; 427 stars; single static binary, no daemon; Python + Node SDKs; CLI; MCP support; rootless, kernel-enforced isolation (github.com/getkern/kern + getkern.dev/guide/sandbox.html, verified 2026-09-28).\n- Vendor-reported benchmarks: ~1/20th the cost of `docker run` per tool call, 21x faster via the prewarm pool, and 7x faster than Docker on library imports — stated here as the vendor's own numbers (vendor-claim), not independently reproduced.\n- Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28."
    },
    {
      "index": 3,
      "heading_path": [
        null,
        "Why it matters for a GTM stack"
      ],
      "est_tokens": 286,
      "text": "benchmarks: ~1/20th the cost of `docker run` per tool call, 21x faster via the prewarm pool, and 7x faster than Docker on library imports — stated here as the vendor's own numbers (vendor-claim), not independently reproduced. - Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28.\n\nThe moment a GTM agent starts running code — parsing a scraped page, transforming an enrichment payload, executing a generated SQL or Python snippet — you need that code contained, and you need it cheap enough to do thousands of times a day. Kern Sandbox targets exactly that: rootless, daemonless isolation you can self-host, addressable over MCP so an agent can call it as a tool, with a prewarm pool aimed at keeping per-call cost low. Open source: yes (Apache-2.0); self-hostable; pricing free. The honest read: the isolation is a container boundary rather than a VM, and the eye-catching cost and speed multiples are the vendor's own benchmarks — pilot it against your real tool-call mix and confirm both the containment guarantees and the numbers before it fronts untrusted execution at scale."
    }
  ],
  "alternates": {
    "markdown": "https://gtmstacker.com/registry/tool/kern-sandbox/index.md",
    "html": "https://gtmstacker.com/registry/tool/kern-sandbox/",
    "json": "https://gtmstacker.com/registry/tool/kern-sandbox/index.json",
    "server_json": "https://gtmstacker.com/registry/tool/kern-sandbox/server.json"
  },
  "jsonld": {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "WebSite",
        "@id": "https://gtmstacker.com/#website",
        "url": "https://gtmstacker.com/",
        "name": "GTM Stacker Agent Registry",
        "description": "A daily-updated, agent-native registry of open-source tool discoveries, tool updates, and curated news for the go-to-market / RevOps engineering niche. Machine-readable first: agents can discover, parse, page, and delta-sync it without scraping HTML.",
        "inLanguage": "en",
        "publisher": {
          "@id": "https://gtmstacker.com/#organization"
        }
      },
      {
        "@type": "Organization",
        "@id": "https://gtmstacker.com/#organization",
        "name": "GTM Stacker",
        "url": "https://gtmstacker.com",
        "description": "The growth-systems practice of Theo Popov: AI-native enrichment, outbound, content engines and internal tooling for startups and venture programs. Its agent-native media property, the GTM Stacker Agent Registry, maintains a daily-updated catalog of open-source go-to-market and RevOps tools that both people and AI engines can discover, compare, and cite.",
        "foundingDate": "2024-08",
        "knowsAbout": [
          "go-to-market engineering",
          "RevOps",
          "sales automation",
          "marketing operations",
          "open-source software",
          "AI agents"
        ],
        "founder": {
          "@type": "Person",
          "@id": "https://gtmstacker.com/#founder",
          "name": "Theo Popov",
          "jobTitle": "Growth Operations & GTM Systems",
          "url": "https://gtmstacker.com/about/",
          "sameAs": [
            "https://www.linkedin.com/in/theo-popov",
            "https://x.com/Theo_Popov",
            "https://github.com/theopopov"
          ],
          "worksFor": {
            "@id": "https://gtmstacker.com/#organization"
          }
        },
        "sameAs": [
          "https://www.linkedin.com/company/gtmstacker",
          "https://www.youtube.com/@gtmstacker",
          "https://www.instagram.com/gtmstacker/",
          "https://www.tiktok.com/@gtmstacker"
        ],
        "mainEntityOfPage": "https://gtmstacker.com/registry/about/"
      },
      {
        "@type": "SoftwareApplication",
        "@id": "https://gtmstacker.com/registry/tool/kern-sandbox/#software",
        "name": "Kern Sandbox",
        "identifier": "getkern/kern",
        "description": "Kern Sandbox is a rootless, daemonless container runtime that runs LLM-generated code and agent tool calls in kernel-enforced isolation, callable from a CLI or Python/Node SDKs with MCP support. Open source: yes (Apache-2.0); self-hostable; pricing free. Single static binary; 427 stars; active.",
        "applicationCategory": "DeveloperApplication",
        "url": "https://gtmstacker.com/registry/tool/kern-sandbox/",
        "datePublished": "2026-09-28T00:00:00Z",
        "dateModified": "2026-09-28T00:00:00Z",
        "isPartOf": {
          "@id": "https://gtmstacker.com/#website"
        },
        "softwareHelp": "https://getkern.dev/guide/sandbox.html",
        "license": "https://spdx.org/licenses/Apache-2.0.html",
        "codeRepository": "https://github.com/getkern/kern",
        "keywords": "ai-infrastructure, mcp-agents, agent-sandbox, code-execution, isolation, self-hostable",
        "author": {
          "@type": "Organization",
          "name": "getkern",
          "url": "https://github.com/getkern",
          "sameAs": [
            "https://github.com/getkern/kern",
            "https://getkern.dev/guide/sandbox.html"
          ]
        },
        "offers": {
          "@type": "Offer",
          "price": 0,
          "priceCurrency": "USD"
        },
        "isSimilarTo": [
          {
            "@type": "SoftwareApplication",
            "name": "OpenSandbox",
            "url": "https://gtmstacker.com/registry/tool/opensandbox/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          },
          {
            "@type": "SoftwareApplication",
            "name": "BoxHaven",
            "url": "https://gtmstacker.com/registry/tool/boxhaven/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          },
          {
            "@type": "SoftwareApplication",
            "name": "Docker Sandbox Kit Spec",
            "url": "https://gtmstacker.com/registry/news/docker-sandbox-kit-spec/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "@id": "https://gtmstacker.com/registry/tool/kern-sandbox/#breadcrumb",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "GTM Stacker Registry",
            "item": "https://gtmstacker.com/registry/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "AI Infrastructure",
            "item": "https://gtmstacker.com/registry/category/ai-infrastructure/"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Kern Sandbox",
            "item": "https://gtmstacker.com/registry/tool/kern-sandbox/"
          }
        ]
      }
    ]
  },
  "tool": {
    "name": "getkern/kern",
    "repository": {
      "url": "https://github.com/getkern/kern",
      "source": "github"
    },
    "homepage": "https://getkern.dev/guide/sandbox.html"
  }
}
