pkg.sopackage field notes

brew / rank 3515

Install fence with Homebrew

Lightweight sandbox for commands with network and filesystem restrictions. Version 0.1.65 via Homebrew; verified 2026-08-01.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install fence

provider-native install command

overview

Package summary

Lightweight sandbox for commands with network and filesystem restrictions

Commands and aliases

  • fence

history

Project history and usage

Fence is a command sandbox and permission layer for running semi-trusted commands with default-deny network access and configurable filesystem and command rules.

Project history

The official README states that Fence moved from github.com/Use-Tusk/fence to github.com/fencesandbox/fence, with migration instructions for Homebrew tap users and Go installs. GitHub releases show an initial v0.1.0 release in December 2025 and frequent v0.1.x releases through June 2026.

The documentation positions Fence as a host-native sandbox rather than a container or VM. On macOS it uses sandbox-exec; on Linux it uses bubblewrap with Landlock and seccomp.

Adoption history

Fence's official README emphasizes AI coding-agent workflows and names Claude Code, Codex, Amp, Gemini CLI, GitHub Copilot, OpenCode, and Factory CLI as compatible commands. Packaging is still young, with Homebrew tap, Nix, curl installer, Go install, and source builds documented by upstream.

How it is used

Basic usage wraps a command with network access blocked by default. Users can apply templates, monitor blocked requests, deny dangerous commands, configure filesystem read/write rules, and inspect the merged config with fence config show.

Why package nerds care

Fence is significant as a post-agent-era CLI package: instead of being an agent, package manager, or container runtime, it wraps arbitrary developer commands with reusable policy. That makes it relevant to package installation scripts, build scripts, CI jobs, and coding-agent sessions.

Timeline

  • 2025: v0.1.0 released on 2025-12-19.
  • 2026: Project README documents migration from Use-Tusk/fence to fencesandbox/fence.
  • 2026: v0.1.61 released on 2026-06-22.

Related projects

  • The README credits Anthropic's sandbox-runtime as inspiration.
  • bubblewrap, Landlock, seccomp, and macOS sandbox-exec are underlying or related sandboxing technologies.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for fence. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
./fence.jsonc./fence.json~/.config/fence/fence.jsonc~/.config/fence/fence.json

executables

Installed executables

CommandKindExposureNote
fenceexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version0.1.65
manager updated2026-08-01
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:fence
Version0.1.65
Package managerHomebrew
Homepagehttps://github.com/fencesandbox/fence
Repositoryhttps://github.com/fencesandbox/fence
Last updated2026-08-01T03:36:54Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation