Agentic AI Atlasby a5c.ai
OverviewWikiGraphFor AgentsEdgesSearchWorkspace
/
GitHubDocsDiscord
iiRecord
Agentic AI Atlas · Default container sandbox
sandbox:default-containera5c.ai
Search record views/
Record · tabs

Available views

II.Record viewspp. 1 - 1
overviewjsongraph
II.
Sandbox overview

sandbox:default-container

Reference · live

Default container sandbox overview

Standard container-backed sandbox with a workspace-only filesystem overlay, a curated network allowlist for package managers, and a deny-list for the obvious shell-out vectors.

SandboxOutgoing · 1Incoming · 2

Attributes

displayName
Default container sandbox
filesystemPolicy
sandboxed
networkPolicy
allowlist
description
Standard container-backed sandbox with a workspace-only filesystem overlay, a curated network allowlist for package managers, and a deny-list for the obvious shell-out vectors.
fsAllowList
  • /workspace/**
  • /tmp/**
  • /home/agent/.cache/**
fsDenyList
  • /etc/shadow
  • /root/**
  • **/.ssh/**
netAllowList
  • registry.npmjs.org
  • *.pypi.org
  • github.com
  • api.anthropic.com
  • api.openai.com
netDenyList
  • 169.254.169.254
execAllowedBinaries
  • node
  • npm
  • python
  • python3
  • pip
  • git
  • bash
execDeniedBinaries
  • sudo
  • su
  • mount
  • kmod
envVarScope
inherit-allowlist
secretAccessScope
named
auditLogPolicy
structured-jsonl
policyEvaluationPoint
pre-call

Outgoing edges

realizes1
  • layer:9-sandbox·LayerSandbox

Incoming edges

executes_in1
  • invocation:01kqex-invocation-001·Invocation
sandboxed_by1
  • execution:docker-default·ExecutionDocker (default container)

Related pages

No related wiki pages for this record.

Shortcuts

Open in graph
Browse node kind