CLI tool
rderaison/bromure avatar
rderaison/bromure

Bromure: Disposable Linux VMs for Agentic Coding and Web Browsing on macOS

Proper sandboxing for agentic coding and web browsing. Full details, screenshots, and downloads at bromure.io This repo ships two sibling apps, both built on Apple's Virtualization.framework: Bromure, every browser session runs in a throwaway Linux VM.

294 stars17 forksSwiftMIT

At a glance

What is it?
Bromure ships two macOS apps built on Apple's Virtualization.framework: a browser that runs each session in a throwaway Linux VM, and an agentic coding sandbox that keeps secrets out of AI agents via a host-side MITM proxy. The README claims a single boundary that enforces isolation, secret scoping, supply-chain scanning, and prompt-injection detection.
Who is it for?
Bromure is for macOS users who want hardware-level isolation for web browsing or AI coding agents, with a strong emphasis on keeping secrets out of the agent and scanning the supply chain. It is not for teams that need cloud-based isolation or that cannot accept the overhead of running full VMs locally.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly Swift, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The Problem: Agentic Coding and Browsing Share a Blast Radius

AI coding agents like Claude Code and Codex can read files, run commands, and fetch packages. If a prompt injection or a malicious package compromises the agent, it can access your local files, credentials, and network. Similarly, a browser exploit can give an attacker a foothold on your host. Bromure addresses both by running each session in a disposable Linux VM on macOS, using Apple's Virtualization.framework. The README compares this to tools like Docker Sandboxes and Capsem, arguing that most solutions only handle one or two threats, while Bromure claims to handle five at a single boundary. Who is it for? Developers and security-conscious users who want to contain the blast radius of AI agents and web browsing without relying on a vendor cloud.

Two Apps, One Core Mechanism: Virtualization.framework

The repository contains two sibling apps. Bromure Web runs every browser session in a throwaway Linux VM; closing the window destroys the VM. Bromure Agentic Coding provides a sandboxed environment for AI coding agents. Both are built on Apple's Virtualization.framework, which provides hardware-accelerated VMs on macOS. The key architectural claim is that all controls are enforced at a single boundary: a host-side MITM proxy. This proxy swaps fake credentials for real ones on the wire, so the real secrets never enter the VM. The same proxy also performs supply-chain scanning, prompt-injection detection, and credential scoping. This design means the agent cannot reach around the boundary, because it only sees stubs and the proxy decides what to attach to outbound requests.

Getting Started: Downloads and No Explicit Commands

The README directs users to bromure.io for full details, screenshots, and downloads. It does not include installation commands or configuration keys in the repository. The apps are distributed as macOS applications, so installation likely involves downloading a disk image and dragging the app to Applications. The README mentions a CLI for remote access, but gives no commands. The release tags indicate versioning: v4.0.0 for Bromure Web and agentic-coding-v4.5.4 for the coding app. Given the lack of setup documentation in the repo, you should consult bromure.io for specific instructions. The MIT license means you can freely use and modify the code, but the apps are distributed as binaries, so you may not need to build from source.

The MITM Proxy: How Secrets Stay Out

The core mechanism of Bromure Agentic Coding is a host-side MITM proxy. It intercepts outbound requests from the VM and swaps fake credentials for real ones on the wire. This means the agent never sees the real credential, only a stub. The README contrasts this with Docker Sandboxes, which also keeps the raw value out of the VM but attaches the credential to any request, allowing a compromised package to spend it against an allow-listed domain. Bromure's proxy adds per-destination consent and TTLs, so each use of a credential requires approval and expires. This is a meaningful distinction: hiding a token is not the same as governing its use. The proxy is also the point where the model panel, local inference, and remote access plug in, according to the README.

Supply-Chain Scanning and Prompt-Injection Detection

The README lists supply-chain scanning as a built-in feature, using age-gate, OSV, socket.dev, and Delpi. This scans packages before they run in the VM. Prompt-injection detection uses PromptGuard and ModernBERT to scan untrusted content and rules files. This addresses a real gap: many sandboxing tools do not scan packages or detect prompt injection. The README's comparison table shows that most alternatives, including Dev Containers and nono, lack these features. However, the README does not explain how these scanners are integrated or how they handle false positives. You should verify the accuracy of these claims by running the tool, as the repository does not include implementation details.

Limitations and Failure Modes

The README's comparison table reveals gaps in Bromure Web: phishing detection and URL filtering are marked as partial, not full. This means Bromure Web may not block malicious sites as robustly as dedicated enterprise browsers like Talon or Island. Also, the isolation is local, so it requires a Mac with sufficient resources to run VMs; on older hardware, performance may suffer. For the coding app, the MITM proxy is a single point of failure: if it is not configured correctly, either secrets leak or the agent cannot reach the network. The README also notes that a compromised package could still spend a credential against an allow-listed domain if the proxy does not enforce per-use consent, which is a subtle but important caveat. Finally, the README is a marketing document; it lists competitors' limitations but does not independently verify them.

Alternatives and Their Different Approaches

The README compares Bromure to several alternatives. For web browsing, Menlo provides remote isolation in the cloud, which offloads the VM overhead but sends traffic through a vendor. Talon and Island harden Chromium on the local machine but do not isolate the browser from the OS. For agentic coding, Docker Sandboxes uses microVMs but does not scan packages or gate credential use per request. Capsem uses an air-gapped VM but keeps real API keys inside the VM, which is a different threat model. Infisical's Agent Vault is a proxy-only solution, so the agent runs unboxed. The key difference is that Bromure combines hardware isolation with a proxy that enforces multiple controls at one boundary, whereas alternatives typically focus on one or two aspects.

Maintenance and Licensing

The project is under the MIT license, which allows free use, modification, and distribution, with no copyleft obligations. The repository is active, with recent releases in August 2026. Maintenance cost depends on how often you update the apps. The README mentions an Enterprise Manager for fleet-wide inventory and token usage, which suggests a paid tier, but the open-source code is MIT. Upgrading may require re-downloading new versions, but the VM-based architecture means you do not need to rebuild anything. The main maintenance concern is keeping the VM images and scanning databases up to date, which the app likely handles automatically. You should check bromure.io for release notes and upgrade instructions.

Editorial conclusion

Bromure is for macOS users who want hardware-level isolation for web browsing or AI coding agents, with a strong emphasis on keeping secrets out of the agent and scanning the supply chain. It is not for teams that need cloud-based isolation or that cannot accept the overhead of running full VMs locally. Before adopting, verify that your Mac model supports Apple's Virtualization.framework, check the release notes for the web app's phishing and filtering gaps, and confirm that the MITM proxy works with your chosen agent and network setup.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/rderaison-bromure.svg)](https://hysenlabs.com/projects/rderaison-bromure)