# Run agents in disposable microVM sandboxes with network allowlists and secret injection using Matchlock

> Launch risky agent work inside disposable microVMs when you need stronger isolation, sealed egress, and host-side secret injection instead of direct host access.

- Skill: `agentskillexchange/run-agents-in-disposable-microvm-sandboxes-with-network-allo` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/run-agents-in-disposable-microvm-sandboxes-with-network-allo`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/run-agents-in-disposable-microvm-sandboxes-with-network-allo/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/run-agents-in-disposable-microvm-sandboxes-with-network-allo

---


# Run agents in disposable microVM sandboxes with network allowlists and secret injection using Matchlock

Launch risky agent work inside disposable microVMs when you need stronger isolation, sealed egress, and host-side secret injection instead of direct host access.

## Prerequisites

Local shell, Matchlock CLI, virtualization support for the target host, and the agent image or command you want to run inside the microVM

## Installation

Use the upstream install or setup path that matches your environment:
- brew tap jingkaihe/essentials
- brew install matchlock
- docker save myapp:latest | matchlock image import myapp:latest # Import from tarball
- pip install matchlock

Requirements and caveats from upstream:
- matchlock run --image python:3.12-alpine \
- --allow-host "api.openai.com" python agent.py
- --secret ANTHROPIC_API_KEY@api.anthropic.com python call_api.py

Basic usage or getting-started notes:
- AI agents need to run code, but giving them unrestricted access to your machine is a risk. Matchlock lets you hand an agent a full Linux environment that boots in under a second - isolated and disposable.
- ### System Requirements
- **Linux** with KVM support

- Source: https://github.com/jingkaihe/matchlock
- Extracted from upstream docs: https://raw.githubusercontent.com/jingkaihe/matchlock/HEAD/README.md

## Documentation

- https://github.com/jingkaihe/matchlock

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/run-agents-in-disposable-microvm-sandboxes-with-network-allowlists-and-secret-injection-using-matchlock/)

