Skip to main content

Secure sandboxed code execution and agent toolbox

Project description

vital-agentbox

Secure sandboxed code execution for AI agents. Runs Python and shell commands inside a Chromium + Pyodide (WASM) sandbox with two independent security boundaries — no host filesystem or network access from agent code.

Features

  • Dual-layer isolation — Chromium renderer sandbox + WASM linear memory
  • Virtual shell — tree-sitter-bash parser with 30+ builtins on in-memory FS
  • Python execution — Pyodide (CPython 3.11 compiled to WASM)
  • Git operations — isomorphic-git on Emscripten MemFS with S3/MinIO storage
  • AI-friendly editingedit builtin with fuzzy + AST-aware matching
  • LangChain & Deep Agents — toolkit, tools, and sandbox backend integrations
  • Scalable — orchestrator + worker architecture with Redis routing

Box types

Type Description
MemBox Ephemeral in-memory sandbox (default)
GitBox MemBox + isomorphic-git + pluggable storage (S3/MinIO/local)
FileSystemBox Local dev only, backed by host directory

Install

# Lightweight client (for LangGraph / Deep Agent apps)
pip install vital-agentbox[client]

# Sandbox worker (runs Chromium + Pyodide)
pip install vital-agentbox[worker]
playwright install chromium

# Orchestrator (routes requests to workers, no Chromium)
pip install vital-agentbox[orchestrator]

# LangChain integration
pip install vital-agentbox[langchain]

Quick start

from agentbox.client import AgentBoxClient

client = AgentBoxClient("http://localhost:8090")

# Create a sandbox
sandbox = client.create_sandbox_sync(box_type="mem")

# Run Python
result = sandbox.execute_sync("print(2 + 2)")
print(result.stdout)  # "4\n"

# Run shell commands
result = sandbox.execute_sync('echo "hello" > /file.txt && cat /file.txt', language="shell")
print(result.stdout)  # "hello\n"

# AI-friendly file editing
result = sandbox.execute_sync(
    "edit /file.txt --old 'hello' --new 'world'",
    language="shell",
)

# Cleanup
sandbox.destroy_sync()

LangChain integration

from agentbox.langchain import AgentBoxToolkit

toolkit = AgentBoxToolkit(base_url="http://localhost:8090")
tools = toolkit.get_tools()
# → [CodeExecutionTool, ShellExecutionTool, FileWriteTool, FileReadTool]

Docker

# Full stack (orchestrator + 2 workers + MinIO)
docker compose up

# Single worker
docker run -p 8090:8000 --shm-size=2g agentbox-worker

Documentation

Full documentation is in the docs/ directory:

System requirements

  • Python ≥ 3.11
  • Chromium (via playwright install chromium) — worker only
  • Redis — orchestrator only
  • For PDF generation: pandoc + LaTeX

License

Apache 2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vital_agentbox-0.1.8.tar.gz (175.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vital_agentbox-0.1.8-py3-none-any.whl (225.3 kB view details)

Uploaded Python 3

File details

Details for the file vital_agentbox-0.1.8.tar.gz.

File metadata

  • Download URL: vital_agentbox-0.1.8.tar.gz
  • Upload date:
  • Size: 175.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.2

File hashes

Hashes for vital_agentbox-0.1.8.tar.gz
Algorithm Hash digest
SHA256 b74d00378eff0d11c5a1e43b809f86f269f5d6c1cd45c8b2e96987f9ce873124
MD5 037b2b7ae76a2c550a9b2edabc3c24a2
BLAKE2b-256 c92eda7fd3781f33a4ea973bfcc5ceb7cbaae0012ccb3c633064feb44583fab5

See more details on using hashes here.

File details

Details for the file vital_agentbox-0.1.8-py3-none-any.whl.

File metadata

  • Download URL: vital_agentbox-0.1.8-py3-none-any.whl
  • Upload date:
  • Size: 225.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.2

File hashes

Hashes for vital_agentbox-0.1.8-py3-none-any.whl
Algorithm Hash digest
SHA256 13763ac9839350b42b021bef0d7559c9a84fa1c53a87002c1d4c96eed278fa81
MD5 67129e33f979eddb507075fcbeb9f947
BLAKE2b-256 c26a67abca6b52e61b7173a2b3980bf3981f08ff4284dfdf57248c176b338829

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page