BoxLite ranks #1 of 10 AI sandboxes on HVTracker's trust score
BoxLite is the only AI sandbox on HVTracker with an A grade, and the only one whose releases carry build provenance.

On October 3, 2026, BoxLite ranked first of the ten projects in HVTracker's Sandboxes & Runtimes category, with an HVTrust score of 85.6. It was the only sandbox with an A grade, ahead of E2B (78.2) and NVIDIA's OpenShell (73.6).

Source: hvtracker.net, Sandboxes & Runtimes, updated 2026-10-03 12:10 UTC.
What the score measures
HVTracker scores open-source AI agent projects on public, checkable signals, and doesn't take vendor claims into account. HVTrust is weighted toward the signals that are hardest to fake: build provenance, signed commits and the OSSF Scorecard. Maintenance and adoption make up the rest.
In other words, it answers one question about a sandbox: can you trust the package you install? That matters more for a sandbox than for most software. A sandbox is the one thing you install specifically to run code you don't trust, and if the package itself is compromised, the isolation it promises doesn't matter. It's usually easier to poison a release than to break a hypervisor.
| Rank | Project | HVTrust | Grade | Build provenance | Signed commits |
| 1 | BoxLite | 85.6 | A | npm and PyPI | 100% |
| 2 | E2B | 78.2 | B | none | 81% |
| 3 | OpenShell | 73.6 | B | none | 100% |
| 4 | OpenSandbox | 71.5 | B | none | 7% |
| 5 | Cube Sandbox | 71.1 | B | none | 79% |
The other five scored below 60. Scores are recomputed daily, so these will move.
Why BoxLite is first
The gap comes from one signal: BoxLite is the only one of the ten that publishes build provenance. Our npm and PyPI releases carry a signed attestation that links each package to the commit and the CI run that built it, and both registries point back to the repository HVTracker tracks. That earns the full 18 points for identity. Every other sandbox in the category scored 10.8.
It isn't popularity. E2B has six times our GitHub stars and about sixty times our weekly downloads, and adoption is 20% of the score. BoxLite still ranks higher, because the signals that are hardest to fake outweigh it.
Where we lose points
The score isn't perfect, and the breakdown is public. Our OSSF Scorecard is 5.2 out of 10, lower than E2B's 6.9 and OpenShell's 6.5. The checks pulling it down are ones we can fix: pinning CI dependencies by hash, scoping workflow token permissions, signing GitHub releases and adding fuzzing. We're working through them, and the score will show it.
What a score can't tell you
HVTrust is one input, not a verdict. It measures how a project is built and shipped. It doesn't measure whether the isolation boundary holds, and it can't see how you deploy it. When you evaluate a sandbox, ask both questions:
- Does the boundary hold? Does each workload get its own kernel, or share the host's?
- Can you verify what you installed? Is every release traceable to its source and the build that produced it?
HVTracker's data is a public answer to the second question. BoxLite's answer to the first has been the same since its first commit: every box is a real virtual machine with its own Linux kernel, isolated in hardware by KVM on Linux and Hypervisor.framework on macOS. A container shares the host kernel, so a container escape lands in the same kernel as everything else on the machine. Escaping a VM is a different class of attack.
Try it
BoxLite ships as an Apache 2.0 runtime you embed in your own program, with no daemon and no control plane, and as BoxLite Cloud, which runs the same boxes behind an API key. Both share one SDK.
pip install boxlite
import asyncio
import boxlite
async def main():
async with boxlite.SimpleBox(image="python:slim") as box:
result = await box.exec("python", "-c", "print(2 + 2)")
print(result.stdout) # "4"
asyncio.run(main())
- Source: https://github.com/boxlite-ai/boxlite
- HVTracker profile: https://hvtracker.net/agents/boxlite/
- Questions: Discord, or support@boxlite.ai
