← Back to list

sandbox-agent
by santiago-afonso
Run agent CLIs (codex/copilot/opencode) inside a Podman sandbox
⭐ 0🍴 0📅 Jan 21, 2026
SKILL.md
name: sandbox-agent description: "Run agent CLIs (codex/copilot/opencode) inside a Podman container with full internet access but filesystem exposure limited to the repo root + explicit bind mounts."
sandbox-agent
Use this when you want:
- Full egress/network for agent CLIs (web search, fetching, etc.)
- Tight filesystem boundaries via container bind mounts (repo root + explicit allowlist)
This repo contains a wrapper script intended to be installed as sandbox-agent.
Workflow
-
Build the image
From the repo root (this repository):
podman build -t localhost/sandbox-agent:latest -f Containerfile .
2. **Install the wrapper**
```bash
install -m 0755 sandbox-agent ~/.local/bin/sandbox-agent
- (Optional) Configure extra mounts
Create ~/.config/sandbox-agent/config.sh:
CODEX_CONTAINER_SANDBOX_IMAGE="localhost/sandbox-agent:latest"
# Extra read-only mounts (mapped under /home/codex/... if under $HOME)
CODEX_CONTAINER_SANDBOX_RO_MOUNTS=(
"$HOME/.local/bin"
)
# Extra read-write mounts
CODEX_CONTAINER_SANDBOX_RW_MOUNTS=(
"$HOME/.cache/uv"
"$HOME/tmp"
)
-
Login once inside the container
sandbox-agent --shell codex login
5. **Run the self-test (recommended)**
```bash
./selftest.sh
If this repo is vendored as a git submodule at ./sandbox-agent/ (for example in a dotfiles repo), either:
cd sandbox-agent && ./selftest.sh, or- run
./sandbox-agent/selftest.shfrom the parent repo root.
- Run an agent CLI
sandbox-agent codex exec "Summarize this repo"
Safety notes
- This wrapper runs with full networking. Anything mounted into the container can be exfiltrated.
- Keep mounts minimal; do not mount secrets, password stores, SSH keys, or large chunks of
$HOMEunless you intend to expose them.
Score
Total Score
50/100
Based on repository quality metrics
✓SKILL.md
SKILL.mdファイルが含まれている
+20
○LICENSE
ライセンスが設定されている
0/10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
Reviews
💬
Reviews coming soon