Reef
skalenetwork/microsandbox-reef
Run Hermes, OpenClaw and your own agents in microsandbox microVMs with TOML-defined policy
Reef is a Rust command-line tool that runs AI agents, including Hermes Agent and OpenClaw, in microsandbox microVMs on your own servers. A reviewable TOML role sets the image, allowed domains and host-bound secrets, and there is no daemon.
What Reef does
Reef runs AI agents in microsandbox microVMs on your own servers, with no daemon. A role is a TOML file that sets the image, resources, the domains an agent may reach and the secrets it may spend, and every agent is created from a role you approved. The README shows roles for OpenClaw and for Hermes Agent, and you can write your own.
The Hermes role needs only four policy lines: egress limited to openrouter.ai, and an OPENROUTER_API_KEY secret bound to that host, so the guest sees only a placeholder. The README credits microsandbox with the microVM, the DNS-enforced egress allowlist and the host-side secret substitution. Opening a port on the reef host requires naming it in the role, and role apply warns about every such opening. Installation is a curl script that places the binary in ~/.local/bin without sudo, on Linux x86_64 and aarch64 or Apple Silicon macOS.
Key features
- Each agent runs in its own microsandbox microVM on your own servers
- Roles defined in a single TOML file: image, resources, egress domains and secrets
- Secrets bound to a host, so the guest sees a placeholder instead of the value
- Approved role versions, with agents on older versions marked stale
- No daemon; every mutating command reconciles inline and VMs outlive reef
- reef role apply, reef fleet apply and reef agent get commands
When to use it
- Limiting a Hermes agent to one domain and one API key
- Running OpenClaw with web access while reef warns about the open egress
- Rolling out the same approved policy to several agents at once
Who it is for: Operators who want to run AI agents on their own servers with strict network and secret boundaries.
How it fits with Hermes Agent
Supports Hermes Agent as one of the agents it can run; the repository includes a roles/hermes.toml and a Hermes fleet example alongside OpenClaw.
How to install Reef
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
curl -fsSL https://reef.clawbits.ai/install | shRequirements: Linux (x86_64 or aarch64, glibc 2.39 or newer) or Apple Silicon macOS, plus the msb bundle from microsandbox
Note: It drives microsandbox rather than shipping it, so each host needs the microsandbox msb bundle.
FAQ
What is Reef?
Reef is a command-line tool that runs AI agents in microsandbox microVMs on your own servers. Each agent is created from an approved TOML role that defines its image, reachable domains and spendable secrets.
Does Reef work with Hermes Agent?
Yes. The README includes a roles/hermes.toml that limits a Hermes agent to openrouter.ai and one bound API key, and a fleet example that starts two Hermes agents with dashboards.
How do I install Reef?
Run curl -fsSL https://reef.clawbits.ai/install | sh. It installs the latest release to ~/.local/bin without sudo, and REEF_VERSION pins a specific version.
Similar security for Hermes Agent
All securityGo command-line password manager with age encryption and an MCP server for AI agents
swytchcodehq Agent Install MonitorLocal history of every package, Docker image and repository your Hermes Agent installs
Adolanium Hermes Plugin ShodanShodan host intel, search, DNS and CVE lookups for Hermes Agent, with credit budgeting
aiconnai AgentShieldOffline Rust scanner for risky behavior in MCP servers and agent tools, with a Hermes Agent adapter
anpicasso Hermes Jev ApprovalsPlugin that serves TypeSafe's Jev model as the reviewer for Hermes Agent smart command approvals
Deconstruct2021 hermes-bumblebee-bridgeDaily read-only supply-chain scans for a Hermes Agent host using Perplexity's Bumblebee
Related guides: How to run Hermes Agent securely