Sandbox
The workspace fence around everything an agent executes.
Agents run real commands on your machine — so nebflow confines them. File writes stay inside the project workspace, sensitive paths are off limits, and every execution is wrapped by an OS-level sandbox.
This page is a preview skeleton — detailed content is being expanded.
The isolation boundary
- OS-native sandboxing — no containers, no virtual machines; it works out of the box on a desktop install
- The same fence applies to the file tools, not just shell commands
Fail-closed by default
- If the sandbox cannot be established, commands fail instead of running unsandboxed
What's protected
- The project workspace is the writable area
- nebflow's own data — credentials, configuration, and agent memory — is never readable from sessions; memory updates go through structured tools
Configuration
sandbox.enabledand the fail-closed switch — covered in detail with this page's full content