Inner Animal Media Inner Animal Media
@inneranimalmedia/agentsam-sdk

Ship Agent Sam with a real SDK computer

npm i @inneranimalmedia/agentsam-sdk — then give agents ephemeral sandboxes, scoped tools, terminals, and promote-only paths back into your Cloudflare stack.

Ephemeral by defaultagentsam-sdk sandboxed runs
Tool-aware accessBYOK + platform secret lanes
Parallel workersparallel tool loops via SDK
Persistent sessionssession state the SDK can resume

Run untrusted code safely

AgentSam can explore packages, run commands, inspect files, and execute generated code without touching your core app infrastructure.

MicroVM isolation

Every risky action runs in a dedicated cloud sandbox instead of your live dashboard, repo, or customer system.

Auth proxy for credentials

Secrets stay behind policy. Agents receive scoped access to only the services, files, and routes that task requires.

Clean blast-radius boundaries

Sandbox file systems, environment variables, package installs, and generated assets are disposable unless promoted.

AgentSam / Sandboxes
policy: locked root isolated
Resource usage CPU
SandboxStartedStatus
sandbox-4f7eb1runs agent-5running
sandbox-b72da4runs agent-8running
sandbox-193af0runs agent-2running
sandbox-567cbb—start soon

From npm install to an agent fleet

The SDK is how products wire Agent Sam: import the client, attach tools, and open sandboxes for codegen, tests, browser research, and repo inspection without inventing a new agent runtime.

One package, many agent workers

Fan out audits, evals, migrations, and build attempts from the same @inneranimalmedia/agentsam-sdk entrypoint your dashboard already uses.

Bring your own stack

Pin Node, Python, ffmpeg, browsers, and repo-specific deps in the sandbox image while the SDK keeps credentials on policy rails.

SDK sandbox request
agentsam-sdk
Proxy Rules

Sessions the SDK can actually resume

Agent Sam sessions stream over the control plane the SDK talks to — keep state across turns, tunnel previews, then tear down when the job is done.

Configurable TTLs

Expire idle sessions automatically so SDK experiments stay cheap and do not become surprise infrastructure.

Snapshot and fork

Snapshot a sandbox the SDK opened, restore it later, or fork alternatives so agents explore safely in parallel.

Port tunneling

Tunnel a preview the SDK opened — app, API, or build — without exposing the whole machine.

sandbox-8530bec8

READYOpen tunnel
Terminal
root@agentsam:~# uname && node -v
Linux
v22.11.0
root@agentsam:~# npm i @inneranimalmedia/agentsam-sdk && agentsam --version
✓ auth proxy policy validated
✓ worker bindings mocked
✓ preview tunnel listening on :8787
streaming logs to Agent Sam control plane...

Observe every agent run before it ships

AgentSam needs more than a terminal. It needs traces, approvals, cost controls, logs, artifacts, and a clear path from experiment to production.

Trace the decision path

See which model, tool, repo, file, command, and sandbox produced each result.

Human approval gates

Let agents build aggressively, then require review before deploys, credential use, data writes, or billing-impacting actions.

Control Plane / agent-run-9074
approvedcost: $0.31
Planner

Reads the issue, creates a safe task graph, and asks for sandboxed execution.

Builder

Runs code, installs packages, executes tests, and returns only promoted artifacts.

GitHubD1R2
Browser

Opens tunnel previews, captures screenshots, and reports UI regressions.

PreviewScreenshot
Reviewer

Summarizes diffs, commands, logs, failures, risk, and what changed.

DiffLogsApproval
spawnsandbox-8530bec8 from repo image184ms
executenpm test, wrangler dry-run, static preview31.4s
promoteartifact bundle + review summary ready2.1s
AgentSam operating layer

Let the agent work hard without giving it your whole system.

This page frames the product story: AgentSam gets a disposable computer, scoped tools, observable execution, and a clean promotion path back into your real Cloudflare, Supabase, GitHub, Gmail, Drive, and design workflows.

01PlanAgentSam defines the task, needed tools, limits, and approval gates.
02ContainA fresh sandbox starts with scoped credentials and task-specific policy.
03ExecuteCode, terminals, previews, tests, and generated assets stay isolated.
04PromoteOnly reviewed files, logs, patches, and artifacts move into production.
Back to top