@inis-run/strands-agents
v0.1.1
Published
inis.run sandbox provider for Strands Agents
Maintainers
Readme
@inis-run/strands-agents
inis.run sandbox provider for Strands Agents' Sandbox surface (@strands-agents/sdk). Gives Strands its standard sandbox_bash and sandbox_file_editor tools backed by a real, isolated inis.run session instead of the local host.
Verified against @strands-agents/sdk==1.11.2. AbortSignal cancellation here can only preempt at a chunk boundary (Session.execStream has no cancellation parameter of its own) — the companion Python package doesn't share this limitation, because asyncio task cancellation preempts regardless.
Install
npm install @inis-run/strands-agents @strands-agents/sdk @inis-run/sdkQuickstart: attached (recommended)
One inis.run session for the whole conversation, owned by your app:
import { Client } from "@inis-run/sdk";
import { Agent } from "@strands-agents/sdk";
import { InisSandbox } from "@inis-run/strands-agents";
const client = new Client();
const session = await client.sessions.create({ egress: { mode: "deny" } });
const sandbox = InisSandbox.wrap(session);
const agent = new Agent({ model, sandbox });
await agent.invoke("list files in /workspace");
await agent.invoke("now write hello.txt");
await session.destroy(); // this app owns the session; the adapter never willOwned: the adapter creates and destroys the session for you
import { Agent } from "@strands-agents/sdk";
import { InisSandbox } from "@inis-run/strands-agents";
const sandbox = await InisSandbox.create(undefined, { egress: { mode: "deny" } });
try {
const agent = new Agent({ model, sandbox });
await agent.invoke("...");
} finally {
await sandbox.close();
}InisSandbox.create()'s opts is CreateSessionOptions from the core
@inis-run/sdk (plus an optional workspaceRoot), so connections —
inline Connections, scoped credential leases bound to a specific external
API origin — works the same way:
const sandbox = await InisSandbox.create(undefined, {
connections: [
{
name: "stripe",
origin: "https://api.stripe.com",
authentication: { type: "bearer", secret: process.env.STRIPE_KEY! },
allow: { methods: ["GET"], paths: ["/v1/customers"] },
},
],
});Either way, new Agent({ sandbox }) registers sandbox_bash and
sandbox_file_editor automatically — no separate tool wiring needed.
Session create/destroy, egress, connections, pause/resume, and fork stay
host-controlled.
What it does
executeStreaming(shell) — distinct stdout/stderr chunks, then a finalExecutionResultexecuteCodeStreaming— inherited fromPosixShellSandbox- Binary-safe
readFile/writeFile/removeFile/listFiles, routed to inis.run's native/filesendpoints - Per-call
timeout— genuinely kills the remote process on expiry - Per-call
env— via a validated shell prefix (inis.run's exec API fixes env at session creation) AbortSignalcancellation — real, but only at a chunk boundary, see above
Notes
PTY isn't implemented: no equivalent in the Sandbox shell/file contract. ExecutionResult.outputFiles is always empty, same as every other shell-based Sandbox — read a produced file with readFile instead.
Development
npm install
npm run build # core @inis-run/sdk must be built first: (cd ../typescript && npm ci && npm run build)
npx tsc --noEmit
npm testLinks
- Docs: docs.inis.run
- Source: github.com/inis-run/sdk/tree/main/strands-agents-js
- Homepage: inis.run
Built and run in the EU. Your code and data never leave Europe.
License
MIT — see LICENSE.
