Systrace for Mac OS X
Niels Provos writes in that he has added Mac OS X support for Systrace, a sandboxing/application confinement tool that can be used to increase application and service security. It installs a new kernel to support /dev/systrace and the Systrace application, and a Cocoa frontend.
Yeah, because if your vendor made it then it must be secure.....
Why not just take a look at the source... its more readily available than the source for Mac OS X.