Built-in Tools
exec runs in the selected Box backend; the other five operate directly on the workspace directory mapped to /workspace. With Host selected, commands also run directly on the Box Runtime host.
These tools target the built-in Agent. When using external runners such as Dify, n8n, Langflow, or Coze, use that platform’s own tool mechanism.
Sandbox Scope
The pipeline’s AI configuration lets you choose how the sandbox is shared across messages. The default “per chat” works for most cases.Lifecycle
These lifecycle rules also apply to Host. Cleanup terminates the session’s managed process trees and removes its temporary session directory. A durable workspace mapped under
box.local.host_root is not deleted as temporary state. Runtime shutdown and explicit session deletion also perform cleanup.
Quick Start
Trusted local development on Linux / macOS can select Host without installing Docker:- Edit
config.yaml: - Start LangBot: Box Runtime is enabled automatically
- In the pipeline, select the built-in Agent plus a model that supports function calling
Disabling Box
Setbox.enabled: false. Everything that depends on the sandbox (built-in tools, Skill create/edit/activate, stdio MCP) is disabled together; MCP servers in http/sse mode are unaffected.
Next Steps
- Sandbox Configuration — backends, security profiles, mounts, environment variables
- Runtimes & Extensions Compared — how the sandbox, Skills, MCP, and plugins divide responsibilities
