Back to Updates

Agent Sandboxes: A Real Linux VM, Locked to Hosts You Allow

ibl.ai Engineering
Applicationiblai/vibe

ibl.ai agents can now run code in a full Linux virtual machine that has no network by default — opened only to the hosts an organization allowlists, with API secrets the agent can use but never read, and runtime billed per second.

ibl.ai agents can now run code in a full Linux virtual machine that has no network by default, opened only to the hosts your organization allows, using API secrets the agent can call with but never read — on ibl.ai, where you own all the code and the data.

The Virtual Machine Shell extends that ownership to what an agent's code can reach.

Network policies, credential-backed secrets and runtime billing reached the platform in the September 25 platform update, and the /iblai-vibe-agent-sandbox skill documented them on September 23, 2026.

The sandbox type is a toggle on an agent's Sandbox tab in Agentic OS; network policies, secrets and their bindings are set by administrators over the platform's REST API.

How do ibl.ai agents run code?

Each agent picks one of three sandbox types on its Sandbox tab. They are mutually exclusive: switching one on switches the others off in the same save.

The Sandbox Type card on an ibl.ai agent's Sandbox tab, reading Choose how this agent runs code. Only one sandbox type can be enabled at a time, with toggles for Computing Runtime, a lightweight JavaScript calculator; Virtual Machine Shell, a full Linux virtual machine, switched on; and Claw, a dedicated persistent worker billed by usage.

  • Computing Runtime — a lightweight JavaScript calculator for quick computations; the low-cost option.
  • Virtual Machine Shell — a full Linux virtual machine in which the agent writes files and runs real shell commands, isolated from everything else.
  • Claw — a dedicated, persistent agent host with its own skills and plugins, billed by usage, and configured through its workspace files.

What can an AI agent's virtual machine reach on the network?

Nothing, until you say otherwise. Every chat runs in its own isolated virtual machine, which starts with no network, and each agent is given one of four egress profiles.

Egress profile What the VM can reach
None (default)No network at all
RegistriesPackage registries only — PyPI, npm, apt and apk
PublicThe public internet, with private ranges, loopback and cloud metadata addresses denied
CustomDeny by default; only the hosts in a named network policy

A network policy is a named allowlist an organization admin writes once and reuses across agents — never across organizations. Entries are exact host:port pairs, with no wildcards and at most 100 per policy; loopback, link-local and metadata addresses are refused outright.

How can an AI agent use an API key without seeing it?

Through VM secrets. Inside the virtual machine, the secret's environment variable holds a placeholder. The real value is substituted only on encrypted requests to the hosts that secret is allowed to reach, so the agent can call the API but cannot print, log or leak the key.

1. Inside the VM
The agent sees ACME_KEY=placeholder — never the real value.
2. The agent calls out
An encrypted request leaves the VM carrying the placeholder.
3. The host is checked
Only a host on the secret's own allowlist gets the substitution.
4. The API gets the key
The real value is swapped in on the way out — and never enters the VM.

A secret either carries its own value or points at one field of a credential the organization already stores for an integration. Pointing at the stored credential means the key is never typed twice, and rotating it once updates every agent that uses it.

The platform also checks the combination. Secrets need the Public or Custom profile, and under Custom every host a secret may reach must also be in the agent's network policy — so a secret can never open a path the policy does not.

Who can configure agent network access, and what does a VM cost?

Only people granted it. Creating, changing or deleting network policies and secrets is a separate permission for each, and organization admins hold them by default. Ordinary users do not, and binding a secret to an agent needs the secret-writing permission too.

VM time is charged to the credits of the person chatting, prorated per second, at $1 per ten minutes by default — a figure each organization can set for itself, and that can be set to zero.

Each session's cost is recorded with the rest of the agent's usage, next to its model calls. Organizations that cap AI spend can do it with spend limits.

The full reference, with every endpoint, is in the /iblai-vibe-agent-sandbox skill.

Want to give your agents real tools without giving up control?

We can walk your security team through a sandboxed agent on your own policies. Book a 30-minute demo or talk to the ibl.ai team — ibl.ai is family-owned and operated from New York, NY.