AIO Sandbox
A Docker container bundling browser, terminal, files, VS Code and MCP services for running agent actions safely in isolation
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Executes arbitrary shell commands and code inside the container on the agent's request
- Without a configured access key the container's services are unauthenticated
- Gives the agent control over the sandbox's browser and filesystem
Install
Manual install
docker run --security-opt seccomp=unconfined --rm -it -e SANDBOX_API_KEY=your-secret-key -p 127.0.0.1:8080:8080 ghcr.io/agent-infra/sandbox:latestRuns the container locally, binding the port only to 127.0.0.1. MCP services become available at http://localhost:8080/mcp.
This is third-party code. Review the repository files before installing.
What it does
AIO Sandbox spins up a single Docker container where a browser with VNC and CDP, a terminal, a filesystem, VS Code Server and Jupyter share one environment. The agent connects through an MCP endpoint or a Python, TypeScript or Go SDK to run commands, read and write files, drive the browser and execute code without touching the host machine. Files the browser downloads inside the sandbox are immediately visible to the shell and file tools because every component shares the same filesystem. The container can be locked down with an access key; without one its API, VNC and Jupyter stay open to anyone who reaches the port.
Who it is for. For developers building agent pipelines who want to run code, downloaded files and browser automation in an isolated environment instead of on their own machine.
Good fit when
- You need an isolated environment where an agent can safely run commands and code
- The agent needs a browser, terminal and file operations at once, sharing one filesystem
- Your own agent connects to a ready MCP hub instead of configuring separate MCP servers for browser, files and shell
Not a fit when
- You only need a simple task without code execution or a browser, where a plain MCP server is enough
- Docker is unavailable or not allowed in the working environment
- You need production multi-tenant isolation: this is a single container for one session, not a multi-tenant platform
Example request
Spin up AIO Sandbox locally and inside the container open this page, take a screenshot and save it as a fileLimitations
Requires Docker and self-hosting; there is no ready hosted service. Without the SANDBOX_API_KEY variable the container's services stay unauthenticated, so the key must be set explicitly. The image is heavy: it bundles a browser, VS Code Server and Jupyter, so the container needs noticeable resources. Some README examples require extra SDKs and Playwright.
How to disable. Stop and remove the container (docker stop and docker rm) and remove the agent-sandbox or @agent-infra/sandbox SDK from your project dependencies.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| SANDBOX_API_KEY secret | Access key for the API, VNC browser and Jupyter. Without it the container's services are open to anyone who can see the port. |
Security check
- Executes arbitrary shell commands and code inside the container on the agent's request
- Without a configured access key the container's services are unauthenticated
- Gives the agent control over the sandbox's browser and filesystem
README in short
The README describes AIO Sandbox as a unified agent sandbox: a browser with VNC and Chrome DevTools Protocol, a terminal, file operations, VS Code Server and Jupyter in one Docker image sharing a filesystem. It starts with docker run publishing port 8080, and code accesses it through the Python package agent-sandbox, the npm package @agent-infra/sandbox or a Go module. It walks through an example where a browser downloads a page, Jupyter converts it to Markdown and the shell reads the result, all on the container's shared disk. Apache-2.0 licensed.
FAQ
How does an agent get access to the sandbox?
Through the container's MCP endpoint at /mcp, or through the Python, TypeScript or Go SDKs that call the same REST API.
Should the container be password protected?
Yes, with the SANDBOX_API_KEY variable. Without it the API, the VNC browser and Jupyter are unauthenticated for anyone who can reach port 8080.
Related
Open-source personal AI assistant on your own machine: answers in Telegram, Slack, Discord and WhatsApp, extended with skills and plugins
A self-improving agent from Nous Research with a TUI, messaging gateway, cron jobs and skills it writes itself
An open source coding agent for the terminal and desktop with build and plan modes
Open prompt library with a Claude Code plugin, MCP server and CLI: search, fetch and improve prompts and skills from an agent