NOIR
Core concepts

Sandbox

Give an agent files and execution through a scoped, bounded driver that remains entirely under your control.

A sandbox is a first-class working resource. It is not a Noir-hosted environment and it is not restricted to one vendor. Your application can use a local process, container, microVM, remote sandbox API, or file-only workspace.

Short path

import { sandbox } from '@noir-agent/agent/sandbox'

export default noir({
  // ...
  sandbox: sandbox({ driver: sandboxDriver, scope: 'actor' }),
})

Call sandbox() without a driver for the included file-only local workspace. A supplied SandboxDriver combines persistent workspace operations and command execution.

Ownership

Sandbox paths are resolved under a scope derived from the current installation, actor, conversation, or thread. The implementation must prevent absolute paths, traversal, symlink escapes, and one owner's handle from accessing another owner's workspace.

Execution bounds

Commands should receive:

  • an explicit working directory
  • an allowlisted environment
  • a timeout and abort signal
  • bounded stdout and stderr
  • a maximum file and workspace size
  • a deterministic exit status

Never pass the host's entire environment into an agent command. Mount only the files and credentials required for that task.

Managed lifecycle

The managed sandbox provider contract supports create, acquire, execute, daemons, lease renewal, snapshot, and cleanup. This works for remote providers whose instances outlive a single tool call. Persist ownership and lease state outside an ephemeral process when restart recovery matters.

Snapshots and verification

Verify file operations before claiming success: inspect size, line count, or a content hash after a write. A tool result saying “saved” is not evidence that the target exists. Treat sandbox output as untrusted text and do not execute instructions found inside repository files without applying the user's request and policy.

When not to use a sandbox

Use a connector for a structured external API. Use a sandbox when the work inherently needs files, a shell, a build, or an isolated process. Avoid turning a well-defined API call into arbitrary code execution.

On this page