ShellTool and ApplyPatchTool primitives, plus the newer SandboxAgent. Mirage provides drop-in replacements that route every shell command, patch, and sandbox call through your Workspace instead of the host.
Install
Tools (ShellTool + ApplyPatchTool)
Sandbox Agent
SandboxAgent runs the SDK’s own exec_command, apply_patch and view_image tools against a sandbox session. MirageSandboxClient makes that session a Mirage workspace, and MirageCapability adds the workspace’s mounts (backend, mode, commands) to the agent’s instructions:
- Every command starts at the manifest root,
/unless you configure aManifest, and acdorexportends with its command, as in the SDK’s other sandboxes. Commands see the manifest’s environment. Each sandbox session has its own Mirage session, and its commands, file reads, writes and patches run in it one at a time. - A command still running after
exec_command’s yield time keeps running. The model polls it withwrite_stdinand stops it with Ctrl-C (\u0003). A directexec(..., timeout=...)raisesExecTimeoutError. - Relative paths resolve against the manifest root, and writes create missing parent directories.
- A run paused for tool approval resumes on the same workspace and keeps the files the agent wrote.
exec("ls", "-la", path, shell=False)quotes each argument. A single string withshell=Falseis one program name, as in the SDK’s other sandboxes.
Exports
Examples
examples/python/agents/openai_agents/ram_agent.py, RAM-only sandbox.examples/python/agents/openai_agents/sandbox_agent.py,SandboxAgentover RAM + S3 + Slack.