Skip to content

Latest commit

 

History

History

README.md

@agentskit/sandbox

Profile: concise-package

AgentsKit

Let agents write and run code safely — in isolated cloud VMs (E2B), constrained local runtimes, or a browser Web Worker.

npm version npm downloads bundle size license stability GitHub stars

Tags: ai · agents · llm · agentskit · ai-agents · sandbox · code-execution · e2b · secure-execution · code-interpreter

Verified proof

How this fits the ecosystem

@agentskit/sandbox gives agents a safer place to execute code and commands instead of trusting arbitrary tool calls in your app process.

  • AgentsKit: compose it with the other packages in this repo to build agents from small, swappable parts.
  • Registry: look for ready agents and templates that already use this layer at registry.agentskit.io.
  • Playbook: learn the production patterns behind this layer at playbook.agentskit.io.
  • AKOS: run the same concepts with enterprise deployment, governance, and observability at akos.agentskit.io.

Docs: package guide · agent handoff

Why sandbox

  • Code generation that actually executes — agents can write, run, and iterate without unrestricted host access
  • E2B cloud VMs — optional peer @e2b/code-interpreter; defaults to no internet (allowInternetAccess: false); per-execute timeout; combined stdout/stderr byte cap
  • Bring your own backendSandboxBackend is two methods; plug in Docker, Firecracker, or any custom isolation layer
  • Policy wrappercreateMandatorySandbox allow/deny/requireSandbox (requireSandbox routes args to the sandbox tool and does not run the original body)
  • Works alongside any other tools — add sandboxTool to the same tools array as webSearch or filesystem

Install

npm install @agentskit/sandbox @e2b/code-interpreter

Quick example

import { createRuntime } from '@agentskit/runtime'
import { anthropic } from '@agentskit/adapters'
import { sandboxTool } from '@agentskit/sandbox'

const runtime = createRuntime({
  adapter: anthropic({ apiKey: process.env.ANTHROPIC_API_KEY, model: 'claude-sonnet-4-6' }),
  tools: [sandboxTool({ apiKey: process.env.E2B_API_KEY })],
})

const result = await runtime.run('Write and run a Python script that generates a Fibonacci sequence up to 100')
console.log(result.content)

Features

  • sandboxTool({ apiKey }) — drop-in tool for code execution via E2B (optional peer)
  • createSandbox({ backend | apiKey, network?, timeout?, language? }) — facade with security defaults
  • Defaults: network: false, timeout: 30_000 ms per execute, language javascript
  • memoryLimit: accepted for compatibility; not enforced by E2B or Web Worker (custom backends may honor it)
  • SandboxBackend interface — execute + optional dispose
  • Local runtimes: process, macOS seatbelt, Linux bwrap (beta), Docker
  • Browser: @agentskit/sandbox/web — Web Worker (thread + DOM isolation only; not WebContainer)
  • Follows ToolDefinition contract — works in runtime, useChat, or any custom loop

Honest isolation claims

Backend What you get What you do not get
E2B Remote VM isolation, optional network deny Per-instance memoryLimit via AgentsKit
Web Worker Off-main-thread + no DOM Network/FS security boundary; WebContainer
processSandbox Child process + env allowlist OS-level fs/net isolation
seatbelt / bwrap / docker Platform jails (beta) A stable multi-tenant guarantee yet

Ecosystem

Package Role
@agentskit/runtime createRuntime({ tools })
@agentskit/tools tools that pair with mandatory sandbox policy
@agentskit/adapters LLM for codegen tasks
@agentskit/core Tool contract

Contributors

AgentsKit contributors

License

MIT — see LICENSE.

Docs

Full documentation · GitHub

Maturity and compatibility

  • Stability: beta — see docs/STABILITY.md. Not 1.0.
  • Node.js 20+ and TypeScript strict mode
  • Published as @agentskit/sandbox

Contributing

See CONTRIBUTING.md and the monorepo LICENSE.