Overview

Loop includes deep container sandboxing powered by Podman. Run AI-generated shell commands and code in isolated containers — protecting your host system from unintended side effects.

Sandbox Modes

Quick Setup

Prerequisites

Install Podman:

Enable Sandbox

In the TUI:
Or with specific options:
--gvisor is an alias for --runsc. /sandbox local with no flags is full isolation on runc.

Check Status

Isolation Levels

Partial Isolation

  • Host filesystem is accessible but path-jailed to your working directory
  • Only bash tool runs inside the container
  • read, write, and edit operate on the host filesystem
  • Good balance of safety and convenience

Full Isolation

  • All tools execute inside the container
  • File operations go through podman exec
  • Your working directory is bind-mounted at the same absolute path inside the container
  • Maximum isolation from the host system

Container Runtimes

Loop supports multiple OCI runtimes for different security profiles:
gVisor (runsc) and krun must be installed separately. See their respective documentation for installation instructions.

Configuration

Settings File

Configure sandbox defaults in ~/.loop/agent/settings.json:

Per-Project Override

In .loop/settings.json (requires project trust):

Command Safety

Even without the container sandbox, Loop includes a built-in command blocklist that prevents dangerous commands:
  • rm -rf /
  • Fork bombs
  • Disk wipe patterns (dd if=/dev/zero)
  • Other destructive operations
The blocklist is applied via check_command_policy before any command executes, regardless of sandbox mode.

How It Works

The SandboxFactory and SandboxRegistry provide pluggable sandbox implementations, allowing custom sandbox backends to be registered.

Disabling the Sandbox

Or in settings: