agentbox
Self-hosted code execution sandbox for AI agents — one docker compose up gives you an HTTP API for running untrusted code in isolated environments.
Status: v0.4 — Python + Node subprocess sandbox, timeouts,
limits.memory_mbviaRLIMIT_AS, TypeScript client, workspace snapshots.
60-second try
docker compose up agentbox # API on :8080
# in another shell:
curl -s http://localhost:8080/health
curl -s -X POST http://localhost:8080/v1/run \
-H 'Content-Type: application/json' \
-d '{"code":"print(sum(range(10)))"}'
docker compose run --rm test # pytest
Why this vs alternatives
| Approach | Strength | Gap |
|---|---|---|
| agentbox | Self-hosted HTTP API + SDK, one compose file | Subprocess isolation today, not gVisor |
| Hosted sandboxes (E2B, etc.) | Strong isolation, managed | Per-second cost; data leaves your network |
Raw docker exec |
Familiar | No agent-oriented API / snapshots / limits |
| YOLO in the agent process | Zero infra | Full host compromise risk |
Problem
Every agent that writes and runs code needs a safe execution environment. Teams either YOLO in shared containers or pay per-second for hosted sandboxes. Self-hosting gVisor/Firecracker is weeks of work.
Key features (v0.4)
- HTTP API:
POST /v1/runexecutes Python or JavaScript - Per-request
limits.timeout_seconds(HTTP 408 on timeout) - Per-request
limits.memory_mb(setsRLIMIT_ASin the child process; 16–8192) - Workspace snapshots:
"snapshot": truethen"snapshot_id" - Python SDK + TypeScript client (
sdk/ts/client.ts) - Docker image includes Node.js for the JS runtime
- Credential stripping when the backend is not
unrestricted
Architecture
Agent / SDK
└── POST /v1/run
└── SubprocessSandbox (MVP)
└── (next) gVisor / Docker backend
| Component | Technology | Why |
|---|---|---|
| API | FastAPI | Async-ready, OpenAPI docs, widely adopted |
| Server | uvicorn | Standard ASGI server |
| Config | pydantic-settings | Typed env config |
| Tests | pytest + httpx TestClient | Fast API testing |
Installation
pip install agentbox-sandbox
pip install -e ".[dev]"
Usage
Start server
agentbox serve
# or
docker compose up agentbox
Run code
curl -X POST http://localhost:8080/v1/run \
-H 'Content-Type: application/json' \
-d '{"code": "print(sum(range(10)))"}'
curl -X POST http://localhost:8080/v1/run \
-H 'Content-Type: application/json' \
-d '{"code": "x = bytearray(10**9)", "limits": {"memory_mb": 64, "timeout_seconds": 5}}'
Python SDK
from agentbox.sdk.client import AgentboxClient
client = AgentboxClient("http://localhost:8080")
print(client.health())
print(client.run("print('hello')"))
print(client.run("console.log('hello')", language="javascript", timeout_seconds=5))
print(client.run("x = bytearray(10**8)", memory_mb=64))
snap = client.run("open('memo.txt','w').write('kept')", snapshot=True)
print(client.run("print(open('memo.txt').read())", snapshot_id=snap["snapshot_id"]))
client.close()
Docker
docker compose up agentbox # start API on :8080
docker compose run --rm test # run unit tests
Configuration
| Variable | Default | Description |
|---|---|---|
AGENTBOX_HOST |
0.0.0.0 |
Bind host |
AGENTBOX_PORT |
8080 |
Bind port |
AGENTBOX_DEFAULT_TIMEOUT_SECONDS |
30 |
Execution timeout |
AGENTBOX_DEFAULT_MEMORY_MB |
unset | Optional default RLIMIT_AS cap |
AGENTBOX_SANDBOX_BACKEND |
subprocess |
Backend selector |
AGENTBOX_SNAPSHOT_DIR |
/tmp/agentbox-snapshots |
Workspace snapshot store |
Running tests
pytest tests/ -v
Roadmap
- Node.js runtime + TypeScript client + per-run timeout
- Filesystem snapshot/restore (tar workspaces)
-
limits.memory_mbviaRLIMIT_AS - gVisor runsc backend with warm pool
- Default-deny egress with allowlists (kernel netns)
License
MIT
Known limitations (v0.4)
- Subprocess sandbox only — not production-grade isolation
RLIMIT_ASis a soft address-space cap, not a cgroup memory controller- Credential stripping is not a network namespace
- Single-node, no warm pool
- TypeScript client is source-only (not published to npm)
Release files for agentbox-sandbox 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agentbox_sandbox-0.4.0.tar.gz | 22.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agentbox_sandbox-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size:33.0 kB
Release files / agentbox_sandbox-0.4.0.tar.gz
| Download URL | agentbox_sandbox-0.4.0.tar.gz |
|---|---|
| Size | 22.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
004ea42c0ca3a184fff2222d4de7f53f3c841de8ee894f479b3efb73310dfedf
|
|
BLAKE2b-256 checksum How to use checksums |
b120c61670925637bd4201437d7a15f190474cab7c0b58ea017d617a2d31a644
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.14
|
Release files / agentbox_sandbox-0.4.0-py3-none-any.whl
| Download URL | agentbox_sandbox-0.4.0-py3-none-any.whl |
|---|---|
| Size | 10.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
fa1822fd585f76f7f1b56039e9b785cfce86c2da6220b0ebf96ddef847bdd6e1
|
|
BLAKE2b-256 checksum How to use checksums |
58bb1c2bc28647facd73c0a603790ac414f845605e839e767534b5bbe4eb4206
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.14
|