Greywall is GreyhavenHQ’s Apache-2.0 Go CLI that sandboxes coding agents on Linux and macOS with bubblewrap, Landlock, seccomp, and eBPF on Linux and Seatbelt on macOS, and it is a fork of Fence that adds what the parent lacks: a companion proxy (greyproxy) that swaps credentials at the HTTP layer, and an allow-by-default watch mode (greywatch) with a live dashboard.
Greywall’s contribution to this category is the observability half of the sandbox workflow, watch first and deny second, with learning mode turning the traces into least-privilege profiles, and its security model states the same ceiling its parent states, defense-in-depth for semi-trusted code, not a boundary against a determined attacker.
What it is #
greywall -- <command> runs with filesystem and network denied by default, command deny rules, and built-in agent profiles for Claude Code, Codex, Cursor, Aider, Goose, Gemini CLI, OpenCode, Amp, Cline, Copilot, Kilo, Auggie, and Droid.
Every connection routes through greyproxy, a companion SOCKS5 proxy with a live allow-and-deny dashboard, so network policy is visible instead of silent.
Credential protection detects credential-bearing environment variables, replaces their values with placeholders, and greyproxy substitutes the actual values at the HTTP layer, so keys never enter the sandbox.
Attribution is stated in the README: Greywall is a fork of Fence, created by JY Tan at Tusk AI, and inspired by Anthropic’s sandbox-runtime; installs come through a Homebrew tap, an install script, or Go, and a Go library surface exists.
Status #
Launched in March 2026 and quiet since: 307 stars, 37 forks, 26 open issues as of 2026-10-08, created 2026-03-04, pushed 2026-08-13, with v0.3.7 (2026-06-01) the last of an April-through-June release train.
The launch got no help from Hacker News: a 7-point Show HN on 2026-03-13, a 1-pointer and a 3-point greyscan submission four days later, and one independent review since. Fifty-six days without a push as of 2026-10-08 leaves a small project with a complete docs site and a stalled train, and the companion greyproxy has been quiet since 2026-06-02.
Strengths #
- Watch-then-restrict is the right order for adopting a sandbox: greywatch runs an agent allow-by-default with every request logged on the dashboard, and learning mode traces filesystem access (strace on Linux, eslogger on macOS) into a least-privilege profile.
- Credential substitution puts the proxy-held-key design the hosted platforms advertise into a workstation CLI: placeholders in the environment, values injected by greyproxy at the HTTP layer.
- Five Linux enforcement layers (bubblewrap namespaces, Landlock, seccomp, eBPF monitoring, TUN capture), documented per OS in a feature matrix rather than marketed.
- The docs state the ceiling in plain words instead of overselling: defense-in-depth for semi-trusted commands, not strong isolation against actively malicious code.
Cautions #
- Fifty-six days without a push as of 2026-10-08 and a release train that stopped at v0.3.7 on 2026-06-01; the fork inherits its parent’s design but not its cadence, since Fence continued on its own org and reached v0.1.67 in September.
- macOS enforcement rides sandbox-exec, which Apple deprecated, the same exposure Fence and aigate carry, and macOS gets no transparent traffic capture because the tun2socks path is Linux-only.
- Kernel primitives only, no VM or gVisor tier, and no independent audit; greywall performs no domain filtering itself, delegating all of it to greyproxy.
- The near-zero Hacker News footprint at 307 stars cuts both ways: little criticism, but also no field reports from users.
Pricing #
Free and open source under Apache-2.0, with greyproxy under MIT; no paid tiers or hosted offering found as of 2026-10-08.
Compared to #
- Fence: the parent project, still maintained on the fencesandbox org; choose Fence for the simpler original on an active train, Greywall for the proxy dashboard, credential substitution, watch, and learning modes.
- nono: the Sigstore team’s broker fences each delegated tool separately and scopes credentials per endpoint; Greywall fences per invocation and swaps credentials at its proxy.
- Drop: the namespace wrapper that keeps your installed distro, with an optional gVisor step-up; Greywall is lighter on the filesystem layer and adds the observability loop Drop lacks.
- aigate: the dormant fourteen-star reference in the same slot; Greywall is what that idea looks like with documentation and a dashboard.
Bottom line #
Recommended for engineers who want to see what an agent actually reaches before fencing it, and who accept a stalled fork with no audit. Not for containing actively malicious code (its own docs say so), and not as the boundary for anyone who needs a maintained release train today, which points back to Fence or OpenShell.
Changes #
- 2026-10-08 - Created from the orchestration worker’s cross-category flag, resolved this run: the Fence fork with proxy-held credential substitution and the watch-then-restrict workflow, its quiet-since-August state recorded.
See also #
- Fence - the parent project Greywall forked from
- Sandboxing Feature Matrix - the category comparison this note joins
- nono - the per-tool broker on the same kernel primitives
- aigate - the dormant small-scale reference in the same slot
- OpenShell - the vendor-backed runtime when policy needs organizational weight
References #
https://github.com/GreyhavenHQ/greywall - repository, README, fork attribution, agent profiles, platform table
https://api.github.com/repos/GreyhavenHQ/greywall - stars, forks, issues, creation and push dates as of 2026-10-08
https://api.github.com/repos/GreyhavenHQ/greywall/releases - the v0.3.3 through v0.3.7 release record ending 2026-06-01
https://github.com/GreyhavenHQ/greyproxy - the companion proxy, MIT, the credential-substitution target
https://docs.greywall.io/greywall/security-model - the semi-trusted-code threat model statement
https://docs.greywall.io/greywall/platform-support - the per-OS enforcement matrix
https://docs.greywall.io/greywall/credential-protection - the placeholder-substitution mechanism
https://greywall.io - the project site
https://hn.algolia.com/api/v1/search?query=greywall&tags=story - the near-zero Hacker News footprint (7, 1, and 3 points)
https://www.wshoffner.dev/blog/greywall - the one independent review, 2026-03-30