Repository files navigation

Agent Box

Fedora Linux (ARM64) + Homebrew + your dotfiles, packaged as a Docker image intended for running agents in an isolated environment.

Security / Isolation Model

This image is primarily a repeatable, throwaway dev environment and a host OS risk reducer. It is not a complete “agent sandbox”.

What it does try to isolate:

  • Your host OS/tooling from installs and filesystem churn (everything happens inside the container)
  • Accidental privilege escalation via the “hardened” run flags (drops Linux capabilities and enables no-new-privileges)

What it does not protect you from:

  • Data loss or exfiltration of anything you mount into the container (especially /workspace)
  • Network exfiltration (unless you run with networking disabled)
  • Damage to persistent state in the home volume (agent-box-home), including ~/.codex/* and other caches/credentials
  • Host-level impact if you mount powerful interfaces like /var/run/docker.sock or run with --privileged

Practical guidance:

  • Treat anything mounted into /workspace as fully trusted / disposable.
  • Prefer the default “hardened” run. Use agent-box-loose only when you explicitly need it.
  • If you care about exfiltration, run with --network none (or a restricted network) and only enable networking when needed.

Build

cd /path/to/agent-box
docker compose build

This project targets linux/arm64 so Apple Silicon can build and run natively (no Rosetta requirement). Homebrew and dotfiles are installed/applied during the image build.

Run

From the directory you want mounted into /workspace, run:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
--cap-drop=ALL \
--security-opt no-new-privileges \
--pids-limit 512 \
--memory 8g \
--cpus 4 \
agent-box:latest

This uses:

  • A persistent home volume at /home/agentbox (agent-box-home)
  • A bind mount of your current directory at /workspace

On first run, Docker copies the image’s /home/agentbox into the empty agent-box-home volume, so your dotfiles, chezmoi state, and Codex config files are present automatically.

Shell Aliases (optional)

Add these to your ~/.zshrc or ~/.bashrc so you can launch the container from any directory (mounting the current directory into /workspace):

alias agent-box='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ --cap-drop=ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 8g \ --cpus 4 \ agent-box:latest'alias agent-box-loose='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ agent-box:latest'

Usage examples:

agent-box
agent-box zsh
agent-box-loose
agent-box-loose zsh

Loose Runtime

If you need a “more powerful” environment (e.g., working sudo inside the container), run without the hardened flags:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
agent-box:latest

Notes:

  • The default (hardened) run drops all Linux capabilities and enables no-new-privileges; setuid programs (like sudo) won’t work.
  • Adjust limits/flags to fit your machine.

Common Tasks

Codex Auth

Credentials are not baked into the image. Authenticate from inside the running container, and the resulting auth state is stored in the persistent agent-box-home volume.

Update Container Dependencies

  • Edit Brewfile.linux
  • Rebuild:
(cd /path/to/agent-box && docker compose build --no-cache)

Tip: rebuilding the image won’t overwrite an existing home volume; to start fresh, remove agent-box-home

Reset Home Directory

This deletes the persistent home volume (dotfiles, caches, history, etc.):

docker volume rm agent-box-home

About

Container image for prevent AI agents from messing up your machine

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Agent Box

Fedora Linux (ARM64) + Homebrew + your dotfiles, packaged as a Docker image intended for running agents in an isolated environment.

Security / Isolation Model

This image is primarily a repeatable, throwaway dev environment and a host OS risk reducer. It is not a complete “agent sandbox”.

What it does try to isolate:

  • Your host OS/tooling from installs and filesystem churn (everything happens inside the container)
  • Accidental privilege escalation via the “hardened” run flags (drops Linux capabilities and enables no-new-privileges)

What it does not protect you from:

  • Data loss or exfiltration of anything you mount into the container (especially /workspace)
  • Network exfiltration (unless you run with networking disabled)
  • Damage to persistent state in the home volume (agent-box-home), including ~/.codex/* and other caches/credentials
  • Host-level impact if you mount powerful interfaces like /var/run/docker.sock or run with --privileged

Practical guidance:

  • Treat anything mounted into /workspace as fully trusted / disposable.
  • Prefer the default “hardened” run. Use agent-box-loose only when you explicitly need it.
  • If you care about exfiltration, run with --network none (or a restricted network) and only enable networking when needed.

Build

cd /path/to/agent-box
docker compose build

This project targets linux/arm64 so Apple Silicon can build and run natively (no Rosetta requirement). Homebrew and dotfiles are installed/applied during the image build.

Run

From the directory you want mounted into /workspace, run:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
--cap-drop=ALL \
--security-opt no-new-privileges \
--pids-limit 512 \
--memory 8g \
--cpus 4 \
agent-box:latest

This uses:

  • A persistent home volume at /home/agentbox (agent-box-home)
  • A bind mount of your current directory at /workspace

On first run, Docker copies the image’s /home/agentbox into the empty agent-box-home volume, so your dotfiles, chezmoi state, and Codex config files are present automatically.

Shell Aliases (optional)

Add these to your ~/.zshrc or ~/.bashrc so you can launch the container from any directory (mounting the current directory into /workspace):

alias agent-box='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ --cap-drop=ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 8g \ --cpus 4 \ agent-box:latest'alias agent-box-loose='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ agent-box:latest'

Usage examples:

agent-box
agent-box zsh
agent-box-loose
agent-box-loose zsh

Loose Runtime

If you need a “more powerful” environment (e.g., working sudo inside the container), run without the hardened flags:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
agent-box:latest

Notes:

  • The default (hardened) run drops all Linux capabilities and enables no-new-privileges; setuid programs (like sudo) won’t work.
  • Adjust limits/flags to fit your machine.

Common Tasks

Codex Auth

Credentials are not baked into the image. Authenticate from inside the running container, and the resulting auth state is stored in the persistent agent-box-home volume.

Update Container Dependencies

  • Edit Brewfile.linux
  • Rebuild:
(cd /path/to/agent-box && docker compose build --no-cache)

Tip: rebuilding the image won’t overwrite an existing home volume; to start fresh, remove agent-box-home

Reset Home Directory

This deletes the persistent home volume (dotfiles, caches, history, etc.):

docker volume rm agent-box-home

About

Container image for prevent AI agents from messing up your machine

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Agent Box

Fedora Linux (ARM64) + Homebrew + your dotfiles, packaged as a Docker image intended for running agents in an isolated environment.

Security / Isolation Model

This image is primarily a repeatable, throwaway dev environment and a host OS risk reducer. It is not a complete “agent sandbox”.

What it does try to isolate:

  • Your host OS/tooling from installs and filesystem churn (everything happens inside the container)
  • Accidental privilege escalation via the “hardened” run flags (drops Linux capabilities and enables no-new-privileges)

What it does not protect you from:

  • Data loss or exfiltration of anything you mount into the container (especially /workspace)
  • Network exfiltration (unless you run with networking disabled)
  • Damage to persistent state in the home volume (agent-box-home), including ~/.codex/* and other caches/credentials
  • Host-level impact if you mount powerful interfaces like /var/run/docker.sock or run with --privileged

Practical guidance:

  • Treat anything mounted into /workspace as fully trusted / disposable.
  • Prefer the default “hardened” run. Use agent-box-loose only when you explicitly need it.
  • If you care about exfiltration, run with --network none (or a restricted network) and only enable networking when needed.

Build

cd /path/to/agent-box
docker compose build

This project targets linux/arm64 so Apple Silicon can build and run natively (no Rosetta requirement). Homebrew and dotfiles are installed/applied during the image build.

Run

From the directory you want mounted into /workspace, run:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
--cap-drop=ALL \
--security-opt no-new-privileges \
--pids-limit 512 \
--memory 8g \
--cpus 4 \
agent-box:latest

This uses:

  • A persistent home volume at /home/agentbox (agent-box-home)
  • A bind mount of your current directory at /workspace

On first run, Docker copies the image’s /home/agentbox into the empty agent-box-home volume, so your dotfiles, chezmoi state, and Codex config files are present automatically.

Shell Aliases (optional)

Add these to your ~/.zshrc or ~/.bashrc so you can launch the container from any directory (mounting the current directory into /workspace):

alias agent-box='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ --cap-drop=ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 8g \ --cpus 4 \ agent-box:latest'alias agent-box-loose='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ agent-box:latest'

Usage examples:

agent-box
agent-box zsh
agent-box-loose
agent-box-loose zsh

Loose Runtime

If you need a “more powerful” environment (e.g., working sudo inside the container), run without the hardened flags:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
agent-box:latest

Notes:

  • The default (hardened) run drops all Linux capabilities and enables no-new-privileges; setuid programs (like sudo) won’t work.
  • Adjust limits/flags to fit your machine.

Common Tasks

Codex Auth

Credentials are not baked into the image. Authenticate from inside the running container, and the resulting auth state is stored in the persistent agent-box-home volume.

Update Container Dependencies

  • Edit Brewfile.linux
  • Rebuild:
(cd /path/to/agent-box && docker compose build --no-cache)

Tip: rebuilding the image won’t overwrite an existing home volume; to start fresh, remove agent-box-home

Reset Home Directory

This deletes the persistent home volume (dotfiles, caches, history, etc.):

docker volume rm agent-box-home

About

Container image for prevent AI agents from messing up your machine

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Agent Box

Fedora Linux (ARM64) + Homebrew + your dotfiles, packaged as a Docker image intended for running agents in an isolated environment.

Security / Isolation Model

This image is primarily a repeatable, throwaway dev environment and a host OS risk reducer. It is not a complete “agent sandbox”.

What it does try to isolate:

  • Your host OS/tooling from installs and filesystem churn (everything happens inside the container)
  • Accidental privilege escalation via the “hardened” run flags (drops Linux capabilities and enables no-new-privileges)

What it does not protect you from:

  • Data loss or exfiltration of anything you mount into the container (especially /workspace)
  • Network exfiltration (unless you run with networking disabled)
  • Damage to persistent state in the home volume (agent-box-home), including ~/.codex/* and other caches/credentials
  • Host-level impact if you mount powerful interfaces like /var/run/docker.sock or run with --privileged

Practical guidance:

  • Treat anything mounted into /workspace as fully trusted / disposable.
  • Prefer the default “hardened” run. Use agent-box-loose only when you explicitly need it.
  • If you care about exfiltration, run with --network none (or a restricted network) and only enable networking when needed.

Build

cd /path/to/agent-box
docker compose build

This project targets linux/arm64 so Apple Silicon can build and run natively (no Rosetta requirement). Homebrew and dotfiles are installed/applied during the image build.

Run

From the directory you want mounted into /workspace, run:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
--cap-drop=ALL \
--security-opt no-new-privileges \
--pids-limit 512 \
--memory 8g \
--cpus 4 \
agent-box:latest

This uses:

  • A persistent home volume at /home/agentbox (agent-box-home)
  • A bind mount of your current directory at /workspace

On first run, Docker copies the image’s /home/agentbox into the empty agent-box-home volume, so your dotfiles, chezmoi state, and Codex config files are present automatically.

Shell Aliases (optional)

Add these to your ~/.zshrc or ~/.bashrc so you can launch the container from any directory (mounting the current directory into /workspace):

alias agent-box='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ --cap-drop=ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 8g \ --cpus 4 \ agent-box:latest'alias agent-box-loose='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ agent-box:latest'

Usage examples:

agent-box
agent-box zsh
agent-box-loose
agent-box-loose zsh

Loose Runtime

If you need a “more powerful” environment (e.g., working sudo inside the container), run without the hardened flags:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
agent-box:latest

Notes:

  • The default (hardened) run drops all Linux capabilities and enables no-new-privileges; setuid programs (like sudo) won’t work.
  • Adjust limits/flags to fit your machine.

Common Tasks

Codex Auth

Credentials are not baked into the image. Authenticate from inside the running container, and the resulting auth state is stored in the persistent agent-box-home volume.

Update Container Dependencies

  • Edit Brewfile.linux
  • Rebuild:
(cd /path/to/agent-box && docker compose build --no-cache)

Tip: rebuilding the image won’t overwrite an existing home volume; to start fresh, remove agent-box-home

Reset Home Directory

This deletes the persistent home volume (dotfiles, caches, history, etc.):

docker volume rm agent-box-home

About

Container image for prevent AI agents from messing up your machine

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Agent Box

Fedora Linux (ARM64) + Homebrew + your dotfiles, packaged as a Docker image intended for running agents in an isolated environment.

Security / Isolation Model

This image is primarily a repeatable, throwaway dev environment and a host OS risk reducer. It is not a complete “agent sandbox”.

What it does try to isolate:

  • Your host OS/tooling from installs and filesystem churn (everything happens inside the container)
  • Accidental privilege escalation via the “hardened” run flags (drops Linux capabilities and enables no-new-privileges)

What it does not protect you from:

  • Data loss or exfiltration of anything you mount into the container (especially /workspace)
  • Network exfiltration (unless you run with networking disabled)
  • Damage to persistent state in the home volume (agent-box-home), including ~/.codex/* and other caches/credentials
  • Host-level impact if you mount powerful interfaces like /var/run/docker.sock or run with --privileged

Practical guidance:

  • Treat anything mounted into /workspace as fully trusted / disposable.
  • Prefer the default “hardened” run. Use agent-box-loose only when you explicitly need it.
  • If you care about exfiltration, run with --network none (or a restricted network) and only enable networking when needed.

Build

cd /path/to/agent-box
docker compose build

This project targets linux/arm64 so Apple Silicon can build and run natively (no Rosetta requirement). Homebrew and dotfiles are installed/applied during the image build.

Run

From the directory you want mounted into /workspace, run:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
--cap-drop=ALL \
--security-opt no-new-privileges \
--pids-limit 512 \
--memory 8g \
--cpus 4 \
agent-box:latest

This uses:

  • A persistent home volume at /home/agentbox (agent-box-home)
  • A bind mount of your current directory at /workspace

On first run, Docker copies the image’s /home/agentbox into the empty agent-box-home volume, so your dotfiles, chezmoi state, and Codex config files are present automatically.

Shell Aliases (optional)

Add these to your ~/.zshrc or ~/.bashrc so you can launch the container from any directory (mounting the current directory into /workspace):

alias agent-box='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ --cap-drop=ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 8g \ --cpus 4 \ agent-box:latest'alias agent-box-loose='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ agent-box:latest'

Usage examples:

agent-box
agent-box zsh
agent-box-loose
agent-box-loose zsh

Loose Runtime

If you need a “more powerful” environment (e.g., working sudo inside the container), run without the hardened flags:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
agent-box:latest

Notes:

  • The default (hardened) run drops all Linux capabilities and enables no-new-privileges; setuid programs (like sudo) won’t work.
  • Adjust limits/flags to fit your machine.

Common Tasks

Codex Auth

Credentials are not baked into the image. Authenticate from inside the running container, and the resulting auth state is stored in the persistent agent-box-home volume.

Update Container Dependencies

  • Edit Brewfile.linux
  • Rebuild:
(cd /path/to/agent-box && docker compose build --no-cache)

Tip: rebuilding the image won’t overwrite an existing home volume; to start fresh, remove agent-box-home

Reset Home Directory

This deletes the persistent home volume (dotfiles, caches, history, etc.):

docker volume rm agent-box-home

About

Container image for prevent AI agents from messing up your machine

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Agent Box

Fedora Linux (ARM64) + Homebrew + your dotfiles, packaged as a Docker image intended for running agents in an isolated environment.

Security / Isolation Model

This image is primarily a repeatable, throwaway dev environment and a host OS risk reducer. It is not a complete “agent sandbox”.

What it does try to isolate:

  • Your host OS/tooling from installs and filesystem churn (everything happens inside the container)
  • Accidental privilege escalation via the “hardened” run flags (drops Linux capabilities and enables no-new-privileges)

What it does not protect you from:

  • Data loss or exfiltration of anything you mount into the container (especially /workspace)
  • Network exfiltration (unless you run with networking disabled)
  • Damage to persistent state in the home volume (agent-box-home), including ~/.codex/* and other caches/credentials
  • Host-level impact if you mount powerful interfaces like /var/run/docker.sock or run with --privileged

Practical guidance:

  • Treat anything mounted into /workspace as fully trusted / disposable.
  • Prefer the default “hardened” run. Use agent-box-loose only when you explicitly need it.
  • If you care about exfiltration, run with --network none (or a restricted network) and only enable networking when needed.

Build

cd /path/to/agent-box
docker compose build

This project targets linux/arm64 so Apple Silicon can build and run natively (no Rosetta requirement). Homebrew and dotfiles are installed/applied during the image build.

Run

From the directory you want mounted into /workspace, run:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
--cap-drop=ALL \
--security-opt no-new-privileges \
--pids-limit 512 \
--memory 8g \
--cpus 4 \
agent-box:latest

This uses:

  • A persistent home volume at /home/agentbox (agent-box-home)
  • A bind mount of your current directory at /workspace

On first run, Docker copies the image’s /home/agentbox into the empty agent-box-home volume, so your dotfiles, chezmoi state, and Codex config files are present automatically.

Shell Aliases (optional)

Add these to your ~/.zshrc or ~/.bashrc so you can launch the container from any directory (mounting the current directory into /workspace):

alias agent-box='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ --cap-drop=ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 8g \ --cpus 4 \ agent-box:latest'alias agent-box-loose='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ agent-box:latest'

Usage examples:

agent-box
agent-box zsh
agent-box-loose
agent-box-loose zsh

Loose Runtime

If you need a “more powerful” environment (e.g., working sudo inside the container), run without the hardened flags:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
agent-box:latest

Notes:

  • The default (hardened) run drops all Linux capabilities and enables no-new-privileges; setuid programs (like sudo) won’t work.
  • Adjust limits/flags to fit your machine.

Common Tasks

Codex Auth

Credentials are not baked into the image. Authenticate from inside the running container, and the resulting auth state is stored in the persistent agent-box-home volume.

Update Container Dependencies

  • Edit Brewfile.linux
  • Rebuild:
(cd /path/to/agent-box && docker compose build --no-cache)

Tip: rebuilding the image won’t overwrite an existing home volume; to start fresh, remove agent-box-home

Reset Home Directory

This deletes the persistent home volume (dotfiles, caches, history, etc.):

docker volume rm agent-box-home

About

Container image for prevent AI agents from messing up your machine

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Agent Box

Fedora Linux (ARM64) + Homebrew + your dotfiles, packaged as a Docker image intended for running agents in an isolated environment.

Security / Isolation Model

This image is primarily a repeatable, throwaway dev environment and a host OS risk reducer. It is not a complete “agent sandbox”.

What it does try to isolate:

  • Your host OS/tooling from installs and filesystem churn (everything happens inside the container)
  • Accidental privilege escalation via the “hardened” run flags (drops Linux capabilities and enables no-new-privileges)

What it does not protect you from:

  • Data loss or exfiltration of anything you mount into the container (especially /workspace)
  • Network exfiltration (unless you run with networking disabled)
  • Damage to persistent state in the home volume (agent-box-home), including ~/.codex/* and other caches/credentials
  • Host-level impact if you mount powerful interfaces like /var/run/docker.sock or run with --privileged

Practical guidance:

  • Treat anything mounted into /workspace as fully trusted / disposable.
  • Prefer the default “hardened” run. Use agent-box-loose only when you explicitly need it.
  • If you care about exfiltration, run with --network none (or a restricted network) and only enable networking when needed.

Build

cd /path/to/agent-box
docker compose build

This project targets linux/arm64 so Apple Silicon can build and run natively (no Rosetta requirement). Homebrew and dotfiles are installed/applied during the image build.

Run

From the directory you want mounted into /workspace, run:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
--cap-drop=ALL \
--security-opt no-new-privileges \
--pids-limit 512 \
--memory 8g \
--cpus 4 \
agent-box:latest

This uses:

  • A persistent home volume at /home/agentbox (agent-box-home)
  • A bind mount of your current directory at /workspace

On first run, Docker copies the image’s /home/agentbox into the empty agent-box-home volume, so your dotfiles, chezmoi state, and Codex config files are present automatically.

Shell Aliases (optional)

Add these to your ~/.zshrc or ~/.bashrc so you can launch the container from any directory (mounting the current directory into /workspace):

alias agent-box='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ --cap-drop=ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 8g \ --cpus 4 \ agent-box:latest'alias agent-box-loose='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ agent-box:latest'

Usage examples:

agent-box
agent-box zsh
agent-box-loose
agent-box-loose zsh

Loose Runtime

If you need a “more powerful” environment (e.g., working sudo inside the container), run without the hardened flags:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
agent-box:latest

Notes:

  • The default (hardened) run drops all Linux capabilities and enables no-new-privileges; setuid programs (like sudo) won’t work.
  • Adjust limits/flags to fit your machine.

Common Tasks

Codex Auth

Credentials are not baked into the image. Authenticate from inside the running container, and the resulting auth state is stored in the persistent agent-box-home volume.

Update Container Dependencies

  • Edit Brewfile.linux
  • Rebuild:
(cd /path/to/agent-box && docker compose build --no-cache)

Tip: rebuilding the image won’t overwrite an existing home volume; to start fresh, remove agent-box-home

Reset Home Directory

This deletes the persistent home volume (dotfiles, caches, history, etc.):

docker volume rm agent-box-home

About

Container image for prevent AI agents from messing up your machine

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Agent Box

Fedora Linux (ARM64) + Homebrew + your dotfiles, packaged as a Docker image intended for running agents in an isolated environment.

Security / Isolation Model

This image is primarily a repeatable, throwaway dev environment and a host OS risk reducer. It is not a complete “agent sandbox”.

What it does try to isolate:

  • Your host OS/tooling from installs and filesystem churn (everything happens inside the container)
  • Accidental privilege escalation via the “hardened” run flags (drops Linux capabilities and enables no-new-privileges)

What it does not protect you from:

  • Data loss or exfiltration of anything you mount into the container (especially /workspace)
  • Network exfiltration (unless you run with networking disabled)
  • Damage to persistent state in the home volume (agent-box-home), including ~/.codex/* and other caches/credentials
  • Host-level impact if you mount powerful interfaces like /var/run/docker.sock or run with --privileged

Practical guidance:

  • Treat anything mounted into /workspace as fully trusted / disposable.
  • Prefer the default “hardened” run. Use agent-box-loose only when you explicitly need it.
  • If you care about exfiltration, run with --network none (or a restricted network) and only enable networking when needed.

Build

cd /path/to/agent-box
docker compose build

This project targets linux/arm64 so Apple Silicon can build and run natively (no Rosetta requirement). Homebrew and dotfiles are installed/applied during the image build.

Run

From the directory you want mounted into /workspace, run:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
--cap-drop=ALL \
--security-opt no-new-privileges \
--pids-limit 512 \
--memory 8g \
--cpus 4 \
agent-box:latest

This uses:

  • A persistent home volume at /home/agentbox (agent-box-home)
  • A bind mount of your current directory at /workspace

On first run, Docker copies the image’s /home/agentbox into the empty agent-box-home volume, so your dotfiles, chezmoi state, and Codex config files are present automatically.

Shell Aliases (optional)

Add these to your ~/.zshrc or ~/.bashrc so you can launch the container from any directory (mounting the current directory into /workspace):

alias agent-box='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ --cap-drop=ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 8g \ --cpus 4 \ agent-box:latest'alias agent-box-loose='docker run --rm -it --init --platform linux/arm64 \ -v agent-box-home:/home/agentbox \ -v "$PWD":/workspace \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \ --group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \ -e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \ -e TERM="${TERM:-xterm-256color}" \ agent-box:latest'

Usage examples:

agent-box
agent-box zsh
agent-box-loose
agent-box-loose zsh

Loose Runtime

If you need a “more powerful” environment (e.g., working sudo inside the container), run without the hardened flags:

docker run --rm -it --init --platform linux/arm64 \
-v agent-box-home:/home/agentbox \
-v "$PWD":/workspace \
--mount type=bind,src=/run/host-services/ssh-auth.sock,target=/run/host-services/ssh-auth.sock \
--group-add "$(docker run --rm --platform linux/arm64 \ --mount type=bind,src=/run/host-services/ssh-auth.sock,target=/ssh-auth.sock \ agent-box:latest stat -c %g /ssh-auth.sock)" \
-e SSH_AUTH_SOCK=/run/host-services/ssh-auth.sock \
-e TERM="${TERM:-xterm-256color}" \
agent-box:latest

Notes:

  • The default (hardened) run drops all Linux capabilities and enables no-new-privileges; setuid programs (like sudo) won’t work.
  • Adjust limits/flags to fit your machine.

Common Tasks

Codex Auth

Credentials are not baked into the image. Authenticate from inside the running container, and the resulting auth state is stored in the persistent agent-box-home volume.

Update Container Dependencies

  • Edit Brewfile.linux
  • Rebuild:
(cd /path/to/agent-box && docker compose build --no-cache)

Tip: rebuilding the image won’t overwrite an existing home volume; to start fresh, remove agent-box-home

Reset Home Directory

This deletes the persistent home volume (dotfiles, caches, history, etc.):

docker volume rm agent-box-home

About

Container image for prevent AI agents from messing up your machine

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages