vital-agentbox
Secure sandboxed code execution for AI agents. Runs Python and shell commands inside a Chromium + Pyodide (WASM) sandbox with two independent security boundaries — no host filesystem or network access from agent code.
Features
- Dual-layer isolation — Chromium renderer sandbox + WASM linear memory
- Virtual shell — tree-sitter-bash parser with 30+ builtins on in-memory FS
- Python execution — Pyodide (CPython 3.11 compiled to WASM)
- Git operations — isomorphic-git on Emscripten MemFS with S3/MinIO storage
- AI-friendly editing —
editbuiltin with fuzzy + AST-aware matching - LangChain & Deep Agents — toolkit, tools, and sandbox backend integrations
- Scalable — orchestrator + worker architecture with Redis routing
Box types
| Type | Description |
|---|---|
| MemBox | Ephemeral in-memory sandbox (default) |
| GitBox | MemBox + isomorphic-git + pluggable storage (S3/MinIO/local) |
| FileSystemBox | Local dev only, backed by host directory |
Install
# Lightweight client (for LangGraph / Deep Agent apps)
pip install vital-agentbox[client]
# Sandbox worker (runs Chromium + Pyodide)
pip install vital-agentbox[worker]
playwright install chromium
# Orchestrator (routes requests to workers, no Chromium)
pip install vital-agentbox[orchestrator]
# LangChain integration
pip install vital-agentbox[langchain]
Quick start
from agentbox.client import AgentBoxClient
client = AgentBoxClient("http://localhost:8090")
# Create a sandbox
sandbox = client.create_sandbox_sync(box_type="mem")
# Run Python
result = sandbox.execute_sync("print(2 + 2)")
print(result.stdout) # "4\n"
# Run shell commands
result = sandbox.execute_sync('echo "hello" > /file.txt && cat /file.txt', language="shell")
print(result.stdout) # "hello\n"
# AI-friendly file editing
result = sandbox.execute_sync(
"edit /file.txt --old 'hello' --new 'world'",
language="shell",
)
# Cleanup
sandbox.destroy_sync()
LangChain integration
from agentbox.langchain import AgentBoxToolkit
toolkit = AgentBoxToolkit(base_url="http://localhost:8090")
tools = toolkit.get_tools()
# → [CodeExecutionTool, ShellExecutionTool, FileWriteTool, FileReadTool]
Docker
# Full stack (orchestrator + 2 workers + MinIO)
docker compose up
# Single worker
docker run -p 8090:8000 --shm-size=2g agentbox-worker
Documentation
Full documentation is in the docs/ directory:
- Getting started
- Sandbox overview
- Shell builtins reference
- Client SDK reference
- REST API reference
- Deployment guide
System requirements
- Python ≥ 3.11
- Chromium (via
playwright install chromium) — worker only - Redis — orchestrator only
- For PDF generation: pandoc + LaTeX
License
Apache 2.0
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
vital_agentbox-0.1.9.tar.gz
(175.5 kB
view details)
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vital_agentbox-0.1.9.tar.gz.
File metadata
- Download URL: vital_agentbox-0.1.9.tar.gz
- Upload date:
- Size: 175.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
fe8193bb36cf8ab1bd27194ae780162ed82d702c039dff587cbb0bbdae4986c1
|
|
| MD5 |
839b99077009da0c58e4cddb5a2a323b
|
|
| BLAKE2b-256 |
197d02bb0b726e77a0afcc7f8fb848a49fe14bb925bffe9ad4011be08d83c963
|
File details
Details for the file vital_agentbox-0.1.9-py3-none-any.whl.
File metadata
- Download URL: vital_agentbox-0.1.9-py3-none-any.whl
- Upload date:
- Size: 225.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b6590b6176ca594590b5c317109294dd9b5e689625edacb9cdae860e527411f5
|
|
| MD5 |
240a23b888b64e9864ad7a3efc68c497
|
|
| BLAKE2b-256 |
5829c3fba1c10cf6e794661abe95e77b5f002106810d73054306e59d68805454
|