Overview
Loop includes deep container sandboxing powered by Podman. Run AI-generated shell commands and code in isolated containers — protecting your host system from unintended side effects.Sandbox Modes
Quick Setup
Prerequisites
Install Podman:- macOS
- Linux
Enable Sandbox
In the TUI:--gvisor is an alias for --runsc. /sandbox local with no flags is full isolation on runc.
Check Status
Isolation Levels
Partial Isolation
- Host filesystem is accessible but path-jailed to your working directory
- Only
bashtool runs inside the container read,write, andeditoperate on the host filesystem- Good balance of safety and convenience
Full Isolation
- All tools execute inside the container
- File operations go through
podman exec - Your working directory is bind-mounted at the same absolute path inside the container
- Maximum isolation from the host system
Container Runtimes
Loop supports multiple OCI runtimes for different security profiles:gVisor (
runsc) and krun must be installed separately. See their respective documentation for installation instructions.Configuration
Settings File
Configure sandbox defaults in~/.loop/agent/settings.json:
Per-Project Override
In.loop/settings.json (requires project trust):
Command Safety
Even without the container sandbox, Loop includes a built-in command blocklist that prevents dangerous commands:rm -rf /- Fork bombs
- Disk wipe patterns (
dd if=/dev/zero) - Other destructive operations
check_command_policy before any command executes, regardless of sandbox mode.
How It Works
SandboxFactory and SandboxRegistry provide pluggable sandbox implementations, allowing custom sandbox backends to be registered.