WASM Sandbox

Every agent runs in a WebAssembly sandbox for security and isolation.

What is Sandboxing?

The WASM sandbox ensures agents:

  • Cannot access the host file system
  • Cannot make network requests (unless granted)
  • Cannot read environment variables (unless granted)
  • Cannot access other agents' memory
  • Cannot spawn processes

Capability Model

Agents start with zero capabilities. You grant what they need:

agents:
  researcher:
    template: researcher
    capabilities:
      network: true       # Allow HTTP requests
      fileRead: true      # Allow reading files
      fileWrite: false    # No file writing
      env:                # Specific env vars
        - API_KEY
        - MODEL

Resource Limits

Resource Default Configurable
Fuel (CPU) 1,000,000 Yes
Memory 16 MB (256 pages) Yes
Stack 1 MB No
Instances 100 concurrent Yes
agents:
  researcher:
    wasm:
      fuel: 5000000        # 5x default
      memoryPages: 512     # 32 MB

Fuel System

Fuel is the WASM equivalent of CPU time. Every instruction consumes fuel. When fuel runs out, the agent is paused.

Start: fuel = 1,000,000
  │
  ├── instruction 1: fuel = 999,999
  ├── instruction 2: fuel = 999,998
  │   ...
  └── fuel = 0 → agent paused

This prevents infinite loops and ensures predictable resource usage.

Security Model

┌─────────────────────────────┐
│        Host System          │
│  ┌───────────────────────┐  │
│  │    WASM Sandbox       │  │
│  │  ┌─────────────────┐  │  │
│  │  │    Agent Code   │  │  │
│  │  │                 │  │  │
│  │  │  No FS access   │  │  │
│  │  │  No net access  │  │  │
│  │  │  No env access  │  │  │
│  │  └─────────────────┘  │  │
│  │                       │  │
│  │  Granted capabilities │  │
│  │  only via host calls  │  │
│  └───────────────────────┘  │
└─────────────────────────────┘