Skip to main content
Each isolation surface in PraisonAI guarantees something different — this page states exactly what, so you never mistake a restriction flag for a real boundary.

Quick Start

1

Isolate an explicit execute_code() call

Agent(sandbox=…) gives you the caller-invoked execute_code() API. It adds no tools and does not isolate tools= callables.
2

Isolate everything the model runs

AgentFlow(run_on="docker") puts the whole workflow inside a real container boundary, so model-driven shell and file tools route through the shared sandbox.

Guarantee Matrix

Each surface below isolates a different thing — read the row before you rely on it.

Why sandbox= is not a capability grant

Agent(sandbox=…) is a restriction flag, not a way to hand the model an execution tool.
Agent(sandbox=…) does not add execute_python_code / execute_shell_command to agent.tools — that auto-injection was reverted in PR #3976. Giving the model a sandboxed execution tool must be a deliberate act by the caller, the way MCP() is. No peer framework grants execution capability from a config flag.
The default subprocess backend enforces none of its own SecurityPolicy on the execute() path:
  • allow_network=False does not block outbound HTTPS.
  • blocked_paths=['~/.ssh', ...] does not stop reading an SSH private key.
  • blocked_imports=['subprocess', ...] does not stop import subprocess.
  • A separate process is not a security boundary.
For real containment, use a real container backend (docker / e2b) or AgentFlow(run_on=…).
praisonai-sandbox must be installed to run any sandbox backend — pip install praisonaiagents alone is not enough. Install a backend, e.g. pip install "praisonai-sandbox[docker]".

Common Patterns


Best Practices

Agent(sandbox=…) configures the explicit execute_code() API. It never hands the model a tool — add one yourself only when you intend the model to run code.
The default subprocess backend is for trusted development only. For untrusted or model-driven execution, use AgentFlow(run_on="docker"), LocalAgent(compute="docker"), or a docker / e2b sandbox backend.
With autonomy=True, the agent still carries the host execute_command tool. sandbox= does not protect that path — isolate the whole workflow with AgentFlow(run_on=…) instead.
pip install praisonaiagents cannot execute any sandbox. Install praisonai-sandbox with the backend you need before relying on isolation.

Sandbox

Configure the explicit execute_code() API and choose a backend

Shared Sandbox

Share one container across every agent with run_on=