Sandbox

The workspace fence around everything an agent executes.

Agents run real commands on your machine — so nebflow confines them. File writes stay inside the project workspace, sensitive paths are off limits, and every execution is wrapped by an OS-level sandbox.

This page is a preview skeleton — detailed content is being expanded.

The isolation boundary

  • OS-native sandboxing — no containers, no virtual machines; it works out of the box on a desktop install
  • The same fence applies to the file tools, not just shell commands

Fail-closed by default

  • If the sandbox cannot be established, commands fail instead of running unsandboxed

What's protected

  • The project workspace is the writable area
  • nebflow's own data — credentials, configuration, and agent memory — is never readable from sessions; memory updates go through structured tools

Configuration

  • sandbox.enabled and the fail-closed switch — covered in detail with this page's full content