MicroVM isolation
Every risky action runs in a dedicated cloud sandbox instead of your live dashboard, repo, or customer system.
npm i @inneranimalmedia/agentsam-sdk — then give agents ephemeral sandboxes, scoped tools, terminals, and promote-only paths back into your Cloudflare stack.
AgentSam can explore packages, run commands, inspect files, and execute generated code without touching your core app infrastructure.
Every risky action runs in a dedicated cloud sandbox instead of your live dashboard, repo, or customer system.
Secrets stay behind policy. Agents receive scoped access to only the services, files, and routes that task requires.
Sandbox file systems, environment variables, package installs, and generated assets are disposable unless promoted.
| Sandbox | Started | Status |
|---|---|---|
| sandbox-4f7eb1 | runs agent-5 | running |
| sandbox-b72da4 | runs agent-8 | running |
| sandbox-193af0 | runs agent-2 | running |
| sandbox-567cbb | — | start soon |
The SDK is how products wire Agent Sam: import the client, attach tools, and open sandboxes for codegen, tests, browser research, and repo inspection without inventing a new agent runtime.
Fan out audits, evals, migrations, and build attempts from the same @inneranimalmedia/agentsam-sdk entrypoint your dashboard already uses.
Pin Node, Python, ffmpeg, browsers, and repo-specific deps in the sandbox image while the SDK keeps credentials on policy rails.
Agent Sam sessions stream over the control plane the SDK talks to — keep state across turns, tunnel previews, then tear down when the job is done.
Expire idle sessions automatically so SDK experiments stay cheap and do not become surprise infrastructure.
Snapshot a sandbox the SDK opened, restore it later, or fork alternatives so agents explore safely in parallel.
Tunnel a preview the SDK opened — app, API, or build — without exposing the whole machine.
root@agentsam:~# uname && node -v Linux v22.11.0 root@agentsam:~# npm i @inneranimalmedia/agentsam-sdk && agentsam --version ✓ auth proxy policy validated ✓ worker bindings mocked ✓ preview tunnel listening on :8787 streaming logs to Agent Sam control plane...
AgentSam needs more than a terminal. It needs traces, approvals, cost controls, logs, artifacts, and a clear path from experiment to production.
See which model, tool, repo, file, command, and sandbox produced each result.
Let agents build aggressively, then require review before deploys, credential use, data writes, or billing-impacting actions.
Reads the issue, creates a safe task graph, and asks for sandboxed execution.
Runs code, installs packages, executes tests, and returns only promoted artifacts.
Opens tunnel previews, captures screenshots, and reports UI regressions.
Summarizes diffs, commands, logs, failures, risk, and what changed.
This page frames the product story: AgentSam gets a disposable computer, scoped tools, observable execution, and a clean promotion path back into your real Cloudflare, Supabase, GitHub, Gmail, Drive, and design workflows.