Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AWS’s Strands Agents Team announced Strands Shell on June 18, 2026: an open-source, Bourne-compatible shell for AI-agent workflows. It can limit what an agent can access, but it is not a hardened security sandbox. The project’s own repository puts it plainly: “Strands Shell is a mediation layer, not a security sandbox.” For hostile code or multi-tenant workloads, the project recommends running it inside a container or microVM.

What Strands Shell does

Strands Shell gives an agent a shell-like environment for tasks such as searching files, running commands, and iterating on code. Developers can expose it through Python, Node.js, or its MCP server. The public repository lists the project under the Apache-2.0 license. The project describes its aim as: “Give your agent a shell without giving it the keys to your machine.”

Rather than letting agent commands run directly as ordinary host shell processes, Strands Shell runs in userspace and mediates access through a Kernel layer. Its design does not use fork, exec, or direct system calls. The project repository lists 25 built-ins and 33 commands; those are documentation counts for a pre-1.0 project and may change.

What it can and cannot protect

The Kernel mediates access to files, network destinations, credentials, and resource use. By default, the environment is empty: an operator must explicitly grant filesystem paths and network destinations, and configure any credentials needed for requests. This can help prevent an agent from casually reaching files or services that were never meant to be part of its task.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That mediation is not equivalent to an operating-system isolation boundary. The Kernel runs in the same process as the host code, and the project says Strands Shell does not protect against shell-engine memory-safety exploits, timing side channels, or an attacker who controls the host process. Its resource limits are best-effort and do not stop an active breakout attempt.

In practical terms, Strands Shell can restrict access in ordinary deployments when configured carefully; it should not be the only barrier around adversarial code or mutually untrusted users. The project recommends placing each Shell instance in a container or microVM for those threat models, and using one Shell instance per session.

How to configure access more safely

Limit filesystem access

  • Grant only the paths the task needs rather than a broad portion of the host filesystem.
  • For source code, prefer copy mode where practical, so the agent works on a copy rather than changing the host files in place.
  • A direct bind is live: changes made through it affect the bound host files. Reserve direct binds for designated output directories where those changes are intended.

Restrict network access

  • Allow only the specific destinations required for the workflow instead of granting broad network access.
  • Keep the documented protections against requests to private addresses and metadata-service endpoints enabled. These SSRF protections reduce risk; they do not make the in-process layer a hardened boundary.

Handle credentials and resource use deliberately

  • Configure credentials for requests rather than exposing secrets directly to the agent.
  • Set command timeouts and output limits to fit the task. These controls help constrain routine resource use, but the project characterizes resource limits as best-effort.
  • Use a separate Shell instance for each session, and add container or microVM isolation when the workload may be hostile.

How Strands Shell differs from a container or cloud sandbox

The key comparison is the security boundary, not just how quickly a shell starts. Strands Shell mediates operations inside the host process; containers and microVMs provide an additional isolation boundary around that process. Which option is appropriate depends on whether the agent runs trusted tasks or untrusted, potentially adversarial workloads.

Option Boundary described Startup figure How to interpret it
Strands Shell In-process mediation Under 1 ms Project-published comparison figure; the repository does not establish an independent benchmark methodology.
Docker Container isolation About 200 ms Project-published comparison figure; not an independently verified benchmark.
Cloud sandbox Cloud sandbox isolation About 1 second Project-published comparison figure; not an independently verified benchmark.

These figures come from the Strands Shell repository’s comparison table, not from an independent test. They are useful as the project’s stated comparison, but they do not establish that the options were measured under identical conditions or that startup speed should decide a security-sensitive deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not confuse Strands Shell with the August 2026 shell vulnerability

AWS’s August 3, 2026 security bulletin concerns CVE-2026-18733 in the consent gate for a separate host shell in the strands-agents-tools package. It is not a vulnerability in Strands Shell. AWS says versions below 0.8.0 were affected and that the issue was addressed in version 0.8.0; its bulletin recommends upgrading. Until upgraded, AWS advises against exposing the affected host shell to agents processing untrusted content and recommends isolated, least-privilege execution.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.