01OS-native sandboxing (macOS `sandbox-exec`, Linux `bubblewrap`)
02Secure-by-default dual isolation with filesystem and network controls
03Minimal performance overhead and near-instant startup times
04Cross-platform support for macOS and Linux
050 GitHub stars
06Highly configurable access rules via CLI or Node.js library