{"_id":"@autosk/sandbox","name":"@autosk/sandbox","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@autosk/sandbox","version":"0.1.0","description":"autosk userspace sandbox library: worktreeSandbox() / dockerSandbox() an agent wraps its harness with, plus sandboxCleanupStep().","license":"MIT","author":{"name":"wierdbytes"},"homepage":"https://github.com/wierdbytes/autosk#readme","repository":{"type":"git","url":"git+https://github.com/wierdbytes/autosk.git","directory":"daemon/extensions/sandbox"},"bugs":{"url":"https://github.com/wierdbytes/autosk/issues"},"keywords":["autosk","autosk-sandbox","autosk-isolation"],"type":"module","publishConfig":{"access":"public"},"exports":{".":"./index.ts"},"types":"./index.ts","dependencies":{"@autosk/sdk":"^0.1.0"},"scripts":{"typecheck":"tsc --noEmit -p tsconfig.json"},"gitHead":"6e4189216039fd42317f92d84106b7415ac1e9dd","_id":"@autosk/sandbox@0.1.0","_nodeVersion":"25.6.1","_npmVersion":"11.9.0","dist":{"integrity":"sha512-zMwf50tFHP0i/63rzXvzuGAq+YW+8n/LpU7iRTp2HycsUal0/BBqJyVNrMWtySt4mHodLjFH/HQWXbyZE0VLHg==","shasum":"1d62b55b55ebb0788f02cc83ab942aed502906ef","tarball":"https://registry.npmjs.org/@autosk/sandbox/-/sandbox-0.1.0.tgz","fileCount":9,"unpackedSize":39725,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCCf6E9jyrZN3wJ+wPH+2kwEafyrj4aZC1xeibwue4VPwIhAOWEkFmVnjJUBBWw5xy8R4mIz+uz7A7HVXcmKH22BVR0"}]},"_npmUser":{"name":"wierdbytes","email":"wb@xff.pw"},"directories":{},"maintainers":[{"name":"wierdbytes","email":"wb@xff.pw"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sandbox_0.1.0_1782167541686_0.7934333677534222"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-22T22:32:21.497Z","0.1.0":"2026-06-22T22:32:21.827Z","modified":"2026-06-22T22:32:22.106Z"},"maintainers":[{"name":"wierdbytes","email":"wb@xff.pw"}],"description":"autosk userspace sandbox library: worktreeSandbox() / dockerSandbox() an agent wraps its harness with, plus sandboxCleanupStep().","homepage":"https://github.com/wierdbytes/autosk#readme","keywords":["autosk","autosk-sandbox","autosk-isolation"],"repository":{"type":"git","url":"git+https://github.com/wierdbytes/autosk.git","directory":"daemon/extensions/sandbox"},"author":{"name":"wierdbytes"},"bugs":{"url":"https://github.com/wierdbytes/autosk/issues"},"license":"MIT","readme":"# @autosk/sandbox\n\nThe userspace **sandbox library** for autoskd v2. Isolation is no longer an\nengine/SDK concept (the `IsolationProvider` abstraction was abolished): agents\nown the isolation they need by wrapping their harness with a `Sandbox` from this\npackage, and teardown is a normal workflow step.\n\nThis package absorbs the retired `@autosk/worktree` and `@autosk/docker`\nproviders. The deterministic slug / branch / container-name derivations are\nbyte-identical, so an already-allocated worktree/branch/container resolves to the\nsame place.\n\n## The `Sandbox` shape (structural)\n\n`Sandbox` is **structural**, not a nominal contract: agents accept any object\nwith these methods, so an operator can hand-roll an exotic sandbox without\ndepending on this package's type.\n\n```ts\ntype Sandbox = {\n  workspace(id): Promise<{ cwd: string }>;          // the per-task dir the harness runs in (idempotent)\n  wrap(cmd, { cwd, env, id }): string[];            // wrap the harness argv (docker run …) — identity for host\n  endpointFor(port): string;                        // host endpoint an in-sandbox process reaches (127.0.0.1 | host.docker.internal)\n  stop(id): Promise<void>;                          // best-effort stop (agent onAbort)\n  cleanup(id, { force }): Promise<{ removed; dirty; detail? }>; // terminal teardown (cleanup step)\n};\n```\n\n## Factories\n\n```ts\nimport { worktreeSandbox, dockerSandbox, sandboxCleanupStep } from \"@autosk/sandbox\";\n\n// per-task git worktree on the host (branch autosk/<task-id>)\nconst sandbox = worktreeSandbox();\n\n// run the harness inside a per-task `docker run -i --rm` container\nconst sandbox = dockerSandbox({ image: \"my-org/autosk-runtime:latest\" });\n```\n\n`dockerSandbox` emits\n`docker run -i --rm --name <det> --add-host=host.docker.internal:host-gateway -v ws:ws -w ws -e … <image> <cmd…>`,\nand `endpointFor` rewrites the host MCP URL to `host.docker.internal` so the\nin-container harness reaches the host. The image is **thin**: just the harness\n(`claude`/`pi`, authenticated) plus the build/test toolchain — no `socat`, no\n`autosk`/`autoskd`, no mounted daemon socket (the agent's tool surface is the\nper-session host HTTP MCP server reached over `host.docker.internal`). Inject\ncredentials / caches via `mounts`, align ownership via `user`, and set the\ncontainer `home`.\n\n## Cleanup as a workflow step\n\n`done`/`cancel` are now a raw status flip with **no** engine teardown — so a\nworkflow that allocates a sandbox MUST route its terminals through a cleanup\nstep or it leaks the worktree on every task:\n\n```ts\nsteps: {\n  dev: claudeAgent({ sandbox, firstMessage }),\n  // …\n  accept: statusStep(\"human\"),\n  cleanup: sandboxCleanupStep(sandbox),\n},\nonTransit(ctx, to) { /* route accept → cleanup, cleanup → done */ },\n```\n\n`sandboxCleanupStep` removes the worktree dir (branch preserved) and any stray\ncontainer, comments the outcome, and transits to its target (default `done`). It\nis idempotent on a missing env.\n","readmeFilename":"README.md","_rev":"1-dc86068a2e0929d9a3a9531032729bc2"}