Microsoft has published a Python library whose entire job is to give an AI agent a computer it is allowed to wreck. The library, Quicksand, boots small virtual machines on demand so an agent can run commands, install software and click around a desktop while your real machine sits outside the blast radius.

Agents that execute shell commands and drive browsers are routine now, and so are stories of them doing something nobody asked for. Containing one used to be a research-lab worry. It is now an everyday question for any team letting a coding agent touch a laptop, which is why a sandbox from Microsoft reads as news rather than plumbing.

The project lives in Microsoft’s microsoft/quicksand repository on GitHub. Its README describes an async Python interface (meaning calls return while the machine works, so one program can keep several going at once) over QEMU, the long-established open-source emulator that does the actual virtualizing. Ready-made Ubuntu and Alpine images ship for x86_64 and ARM64 chips, on macOS, Linux, and Windows. Desktop variants add a graphical environment and a browser, with calls for screenshots, typing, and mouse movement, so an agent that operates a screen has something to operate.

Two lines in the README matter more to an engineer than the rest. Running a sandbox needs no root privileges, and it needs no Docker. The first decides whether you can use the tool at all on a locked-down work machine, where installing anything that demands administrator rights means a ticket and a wait. The second removes a background service that some environments do not permit, and that on Macs and Windows machines quietly runs its own virtual machine anyway. A tool that installs with pip and runs as an ordinary user is one a developer can try this afternoon.

The snapshot feature is the other half of the appeal. You mark a checkpoint, let the agent loose, and if it trashes the system you roll the whole machine back to the mark. The README’s own example installs something risky and then reverts. You can also save a machine’s disk to a folder and load it later, even on another computer. For agent work, that turns destructive mistakes into a thirty-second reset.

Whether a virtual machine is the right wall is a fair question. The README says sandboxes are isolated from the network by default and that internet access and port forwarding are an opt-in setting. That is a sensible default. It is also the setting most real agents will switch on, because an agent that cannot reach the web or an API is not much use. Once it can, the machine does nothing about what the agent sends out, and a rollback cannot unsend a request. Shared host folders carry the same caveat: the protection is only as good as what you mount into the machine. The library can also put several agents in one machine under separate Linux user accounts, which is a thinner boundary than one machine each.

On maturity, the README presents this as a project, not a product. The page names no licence, so it should not be assumed to be open source in the usual sense. It makes no claim of production readiness and says nothing about Microsoft supporting it. The page carries no date for the project itself; the only date it gives is September 14, 2026, for the current image releases. Anyone planning to depend on it should check the repository’s licence file first.

The practical test for a team is narrow: if an agent will run on a company machine, ask whether its network switch stays off, because that is the one thing a snapshot cannot undo.

Microsoft, via the microsoft/quicksand repository on GitHub, whose README carries no publication date.