TenBox
78/tenbox
Lightweight virtual machine monitor for running OpenClaw, QwenPaw and Hermes Agent in isolation
TenBox is a cross-platform virtual machine monitor that runs AI agents inside isolated Linux virtual machines on a personal computer, so an agent can only reach files you explicitly authorize. Its repository description names Hermes Agent, OpenClaw and QwenPaw.
What TenBox does
TenBox is a C++ VMM with backends for WHVP on Windows, Hypervisor Framework on macOS (Apple Silicon and Intel) and KVM on Linux (x86_64 and arm64, including Raspberry Pi). It boots standard Linux kernels with an initramfs and offers VirtIO devices for block, network, GPU, input, serial, sound and filesystem, qcow2 and raw disk images, virtiofs shared folders that can be read-only, and clipboard sharing. Windows and macOS have native GUI managers, and Linux runs a systemd daemon, tenboxd, with a tenbox CLI for creating, starting, stopping and inspecting VMs.
NAT networking with port forwarding lets guest services be exposed on host ports, and a built-in OpenAI-compatible proxy maps guest requests to configurable upstream providers. On Linux a browser-based remote desktop and an eight-digit pairing code flow are included. The Linux installer registers an apt repository and requires glibc 2.31 and /dev/kvm, while Windows and macOS installers come from the website or GitHub Releases.
Key features
- Hypervisor backends: WHVP on Windows, Hypervisor Framework on macOS, KVM on Linux
- Shared folders through virtiofs, optionally read-only
- tenboxd daemon and tenbox CLI on Linux for managing VMs
- Built-in OpenAI-compatible proxy to configurable upstream providers
- NAT networking with host and guest port forwarding
- Browser-based remote desktop on Linux
When to use it
- Running an agent in a VM that sees only folders you share with it
- Hosting an agent on a Raspberry Pi 5 or other Linux box with KVM
- Keeping provider credentials on the host while the guest calls a local proxy
Who it is for: Users who want to run AI agents on their own computer without giving them access to the whole machine.
How it fits with Hermes Agent
The repository description names Hermes Agent, alongside OpenClaw and QwenPaw, as an agent it is built to host, while the VM itself is a general Linux guest.
How to install TenBox
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
curl -fsSL https://tenbox.ai/install.sh | sudo shRequirements: On Linux, Debian 11+, Ubuntu 20.04+ or Raspberry Pi OS 11+ (amd64 or arm64) with glibc 2.31+ and /dev/kvm
FAQ
What is TenBox?
TenBox is a cross-platform virtual machine monitor for running AI agents in isolated Linux VMs. Each agent can only access the files you explicitly share with it.
How do I install TenBox?
On Debian, Ubuntu or Raspberry Pi OS, run curl -fsSL https://tenbox.ai/install.sh | sudo sh, which adds the TenBox apt repository and enables tenboxd. On Windows and macOS, download the installer from tenbox.ai or the GitHub Releases page.
Is TenBox free and open source?
GitHub reports the license as NOASSERTION, meaning it could not identify a standard license. Check the repository's license files before reuse.
Similar security for Hermes Agent
All securityLocal dashboard that reads agent session files to show timelines, tool calls and token costs
runta-dev ClawShellLocal proxy that swaps virtual API keys for real ones and scans traffic for PII, for OpenClaw and Hermes
0xNyk LACPLocal policy, approval and recovery controls that wrap CLI coding agents such as Claude, Codex and Hermes
asimons81 Hermes VaultLocal-first credential broker, secret scanner and encrypted vault for Hermes agents
nativ3ai Hermes Agent CaMeLHermes Agent fork with an opt-in CaMeL-style guard against indirect prompt injection
XSafeAI XSafeClawOpen-source agent safety platform that monitors and guards OpenClaw, Hermes and Nanobot sessions
Related guides: How to run Hermes Agent securely