@agentskit/os-sandbox
v1.0.0-alpha.1
Published
AgentsKitOS sandbox runtimes — built-in none + process; container/vm via plugins.
Maintainers
Readme
@agentskit/os-sandbox
Sandbox runtimes per ADR-0010. Built-in none (in-process) + process (child_process). Container / VM / WebContainer ship as plugins.
Status
Pre-1.0 alpha. M1 ships boundary only — seccomp / job-object hardening lands in M6.
API
noneSandbox— levelnone, rejects all spawn (in-process compute only)processSandbox(opts?)— levelprocess, spawns child processes via injectedSpawner. Strips env to allowlist (PATH,HOME,TZ,LANG,LC_ALL,NODE_ENV,AGENTSKITOS_*).SandboxRegistry— resolvesSandboxLevel→SandboxRuntime. Plugins registercontainer/vm/webcontainer.nodeSpawner()— defaultSpawnerbacked bynode:child_process.spawn.
License
MIT
