Skip to main content
Choose the execution environment before exposing a code or shell tool. SandboxAgent manages a workspace; CloudSandbox is the port used by remote adapters. V4 rejects the unimplemented docker selector. Local execution runs with the host user’s privileges; a temporary directory is not OS isolation.

Workspace or agent tools?

Use SandboxAgent when application code explicitly manages a workspace and calls run, shell, readFile, and writeFile. Use sandbox toolkits when a model should call those operations through tools. Tool approval and execution policy still belong in the Agent or harness that exposes them. A workspace review harness can read selected source files without enabling code execution at all.

Remote failure handling

A request timeout or cancellation may stop local waiting while provider work continues. Inspect the provider before repeating an operation with effects. Both remote adapters serialize starts and close owned sandboxes; missing-file responses become null, while authentication and network errors remain failures. Output bounds are not provider memory quotas.