Skip to content

feat: let agents drive a browser in the sandbox, and people use it with them - #303

Merged
tjholm merged 1 commit into
sandbox-network-accessfrom
sandbox-desktop
Oct 7, 2026
Merged

tjholm merged 1 commit into
sandbox-network-accessfrom
sandbox-desktop

Conversation

@tjholm

@tjholm tjholm commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Agent browser

  • Agents get Playwright MCP's browser_* tools.
  • Each thread runs its own Chromium on the agent's desktop in the pod's sandbox.

Watching and taking over

  • People open the desktop from the Sandbox button at the top of the agent's chat (shows when the agent is using it), or from a browser call in the thread.
  • They can watch, click and type.
  • The API relays a WebSocket to the desktop's VNC server, behind the thread's permissions.
  • Opening it uses the sandbox like a turn would: resumes or makes it, holds it awake, and starts the desktop without a browser. The agent's browser joins the same desktop.

Other

  • read_file shows images to models that accept them.
  • The sandbox interface gains endpoint(port): OpenSandbox's port proxy, or E2B's host (header routing on E2B Embed).

Stack created with GitHub Stacks CLI • Give Feedback 💬

@tjholm
tjholm added this pull request to stack #305 October 6, 2026 03:35
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
sugabots-website 6e9e8ea Oct 07 2026, 11:44 PM

@tjholm
tjholm marked this pull request as ready for review October 7, 2026 02:56
@tjholm
tjholm removed this pull request from stack #305 October 7, 2026 02:58
@tjholm
tjholm added this pull request to stack #327 October 7, 2026 02:58
@tjholm
tjholm force-pushed the sandbox-desktop branch 3 times, most recently from f52f948 to 1ea641d Compare October 7, 2026 06:27
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Sandbox image preview, built from 6e9e8ea:

ghcr.io/nitrictech/sugabots-sandbox:pr-303

To try it, set a sandbox provider's image to that under Sandboxes in the workspace's settings, then Upgrade the pod's sandbox; on E2B, prepare the template again first. The tag moves with each push to this pull request, so a machine that pulled it before may need docker pull again; for this exact build, use ghcr.io/nitrictech/sugabots-sandbox@sha256:b5bf0e74636df6201aedb6dff7ecfaea0e6577c8486a3c3ce05ead3d5aaf99bf.

It's deleted when the pull request closes.

@tjholm
tjholm force-pushed the sandbox-desktop branch 4 times, most recently from d6b68c4 to 3e32870 Compare October 7, 2026 22:39
@tjholm
tjholm force-pushed the sandbox-desktop branch 3 times, most recently from c662645 to 400b52b Compare October 7, 2026 23:29
…th them

Agents get Playwright MCP's browser_ tools, run by a Chromium of their own in each thread on their own desktop in the pod's sandbox. Chromium keeps its own sandbox where the sandbox allows user namespaces, and runs without one where it doesn't. A managed policy keeps pages in it from reaching the sandbox's own network, where Playwright MCP listens without a password, and has it connect without QUIC or Encrypted Client Hello, so egress rules that allow hosts by the name a TLS connection gives let it through. Each desktop's VNC servers take passwords made when it starts, which the API answers with on the person's behalf, so neither the passwords nor the sandbox's address reach the browser. People open that desktop from the Sandbox button at the top of the agent's chat, which says when the agent is using it, or from a browser call in the thread, through a WebSocket the API relays from the desktop's VNC server. Anyone who can read the thread may open the desktop of an agent that takes part in it and uses the sandbox; those with the new sandbox.desktop.use pod permission (members and up) may click and type, and the pod's viewers watch through a view-only VNC server. The viewer disconnects after 5 minutes without input from the person or browser use by the agent. Opening it uses the sandbox as a turn would, resuming or making it, holds it awake, and starts the desktop without a browser; the agent's browser joins the same desktop. read_file shows images to models that take them. The sandbox interface gains endpoint(port), through OpenSandbox's port proxy or E2B's host, with header routing on E2B Embed.
@tjholm
tjholm merged commit 9da3529 into main Oct 7, 2026
9 checks passed
@tjholm
tjholm deleted the sandbox-desktop branch October 7, 2026 23:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant