Skip to contentNew accounts start with $100 in credits Get an API key →
← all posts

BoxLite ranks #1 of 10 AI sandboxes on HVTracker's trust score

BoxLite is the only AI sandbox on HVTracker with an A grade, and the only one whose releases carry build provenance.

Mandalore Wang4 min read

On October 3, 2026, BoxLite ranked first of the ten projects in HVTracker's Sandboxes & Runtimes category, with an HVTrust score of 85.6. It was the only sandbox with an A grade, ahead of E2B (78.2) and NVIDIA's OpenShell (73.6).

HVTracker's Sandboxes & Runtimes leaderboard on October 3, 2026: BoxLite first with 85.6 and an A grade, then E2B at 78.2, OpenShell at 73.6, OpenSandbox at 71.5 and Cube Sandbox at 71.1

Source: hvtracker.net, Sandboxes & Runtimes, updated 2026-10-03 12:10 UTC.

What the score measures

HVTracker scores open-source AI agent projects on public, checkable signals, and doesn't take vendor claims into account. HVTrust is weighted toward the signals that are hardest to fake: build provenance, signed commits and the OSSF Scorecard. Maintenance and adoption make up the rest.

In other words, it answers one question about a sandbox: can you trust the package you install? That matters more for a sandbox than for most software. A sandbox is the one thing you install specifically to run code you don't trust, and if the package itself is compromised, the isolation it promises doesn't matter. It's usually easier to poison a release than to break a hypervisor.

RankProjectHVTrustGradeBuild provenanceSigned commits
1BoxLite85.6Anpm and PyPI100%
2E2B78.2Bnone81%
3OpenShell73.6Bnone100%
4OpenSandbox71.5Bnone7%
5Cube Sandbox71.1Bnone79%

The other five scored below 60. Scores are recomputed daily, so these will move.

Why BoxLite is first

The gap comes from one signal: BoxLite is the only one of the ten that publishes build provenance. Our npm and PyPI releases carry a signed attestation that links each package to the commit and the CI run that built it, and both registries point back to the repository HVTracker tracks. That earns the full 18 points for identity. Every other sandbox in the category scored 10.8.

It isn't popularity. E2B has six times our GitHub stars and about sixty times our weekly downloads, and adoption is 20% of the score. BoxLite still ranks higher, because the signals that are hardest to fake outweigh it.

Where we lose points

The score isn't perfect, and the breakdown is public. Our OSSF Scorecard is 5.2 out of 10, lower than E2B's 6.9 and OpenShell's 6.5. The checks pulling it down are ones we can fix: pinning CI dependencies by hash, scoping workflow token permissions, signing GitHub releases and adding fuzzing. We're working through them, and the score will show it.

What a score can't tell you

HVTrust is one input, not a verdict. It measures how a project is built and shipped. It doesn't measure whether the isolation boundary holds, and it can't see how you deploy it. When you evaluate a sandbox, ask both questions:

  • Does the boundary hold? Does each workload get its own kernel, or share the host's?
  • Can you verify what you installed? Is every release traceable to its source and the build that produced it?

HVTracker's data is a public answer to the second question. BoxLite's answer to the first has been the same since its first commit: every box is a real virtual machine with its own Linux kernel, isolated in hardware by KVM on Linux and Hypervisor.framework on macOS. A container shares the host kernel, so a container escape lands in the same kernel as everything else on the machine. Escaping a VM is a different class of attack.

Try it

BoxLite ships as an Apache 2.0 runtime you embed in your own program, with no daemon and no control plane, and as BoxLite Cloud, which runs the same boxes behind an API key. Both share one SDK.

pip install boxlite
import asyncio
import boxlite

async def main():
    async with boxlite.SimpleBox(image="python:slim") as box:
        result = await box.exec("python", "-c", "print(2 + 2)")
        print(result.stdout)  # "4"

asyncio.run(main())