跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

Supported capability matrix

What each sandbox backend supports for shell, files, workspace, network, browser, and plugin tools

A per-backend comparison of sandbox capabilities, and the Gateway-side execution that stays outside the sandbox boundary.

Supported capability matrix

Sandbox backends isolate tool execution. They do not move the Gateway, native plugins, or control-plane RPC into the sandbox.

CapabilityDockerSSHOpenShell
Shell and child processesSupported inside the containerSupported on the remote hostSupported inside the managed sandbox
File toolsSupported through the container filesystem bridgeSupported through the SSH filesystem bridgeSupported through the SSH bridge in mirror or remote mode
Workspace accessnone, ro, and rwnone, ro, and rwnone, ro, and rw
Network restrictiondocker.network; defaults to "none"Controlled by the remote hostControlled by the selected OpenShell policy
Sandboxed browserSupported in a separate browser containerNot supportedNot supported
Additional host foldersdocker.binds with explicit :ro or :rwNot supported as mounts; seed or copy files insteadNot supported as mounts; use workspace sync or remote files
Packages and runtimesBake a custom image, or use setupCommand with the required privilegesProvision them on the remote hostInclude them in the source image or install when policy permits
Private certificate rootsBake or mount them into the image and configure the consuming runtimeConfigure the remote host trust storeInclude them in the source image or configure them inside sandbox
Plugin and MCP tool accessGateway-side execution, additionally gated by sandbox tool policyGateway-side execution, additionally gated by policyGateway-side execution, additionally gated by sandbox tool policy

Native plugins remain in-process with the Gateway and share its trust boundary. Sandboxed sessions can use plugin-owned and MCP tools only when normal tool policy and tools.sandbox.tools both allow them. See MCP and plugin tools inside sandbox tool policy and Plugin execution model.