Hazmat: Sandboxing AI Coding Agents with Least Privilege
Open-source Hazmat, released on GitHub around August 17, 2026, wraps Claude Code, Codex, OpenCode, and Cursor Agent in a dedicated OS account so coding agents run with least privilege: only the declared project directory is shared and a per-session firewall rule caps network access. This briefing walks the macOS containment flow, the ~5.5% TLA+ formal specification, the demo that proves private keys stay unreadable, and the ROI of OS-account sandboxing versus breach risk.