Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

aasm sandbox

Run a WebAssembly tool inside the Agent Assembly tool-execution sandbox, with filesystem, CPU (instruction fuel), memory, and wall-clock isolation. This surfaces the aa-sandbox runtime to the CLI without going through the cloud /dispatch_tool HTTP route.

Synopsis

aasm sandbox <SUBCOMMAND> [OPTIONS]
SubcommandPurpose
runRun a .wasm module inside a fresh sandbox.
infoShow the default sandbox runtime limits.

aasm sandbox run

Run a WebAssembly module under WASI preview 1 inside a fresh sandbox and report the outcome. Unset limits fall back to the safe-by-default values.

NameTypeDefaultDescription
<WASM>path (arg)Path to a .wasm module to execute under WASI preview 1.
--fuel <FUEL>integer10000000 (10M)Wasmtime instruction-fuel budget. Raise for long-running tools.
--memory-pages <MEMORY_PAGES>integer16 (1 MiB)Maximum linear-memory pages (1 page = 64 KiB).
--wall-clock-ms <WALL_CLOCK_MS>integer5000 (5s)Wall-clock deadline in milliseconds.
aasm sandbox run ./tool.wasm --fuel 50000000 --wall-clock-ms 10000
sandbox exited cleanly (exit_code=0)

On success the command prints a single line with the module’s exit code. If the sandbox refuses or traps the module (fuel exhaustion, memory-cap or wall-clock overrun, or a WASI trap), it instead writes sandbox refused or trapped the module: <reason> to stderr and exits non-zero. Fuel and wall-time usage are not tracked or reported.


aasm sandbox info

Show the default sandbox runtime limits. Takes no arguments.

aasm sandbox info
aasm sandbox — WASI preview 1 tool-execution sandbox
  fuel (instructions):      10000000
  memory ceiling:           16 pages (1024 KiB)
  wall-clock deadline (ms): 5000
  preopened dirs:           (none — fully sealed FS)

Last updated: 2026-07-19 by Bryant