Optional Docker container isolation for running AI coding agents with filesystem protection.
VibeKit’s local sandbox feature optionally runs coding agents inside Docker containers, providing isolation from your host system. The sandbox functionality is available but not enabled by default.
# Enable sandbox for a single commandvibekit claude --sandbox "Help me debug this issue"# Specify sandbox type (docker or podman)vibekit claude --sandbox-type docker "Generate some code"# Use podman instead of dockervibekit claude --sandbox-type podman "Review this function"
Sandbox provides process isolation, not complete security
Container breakout vulnerabilities may still exist
Host filesystem mounts reduce isolation benefits
Keep container runtime updated for security patches
The local sandbox feature provides an additional layer of protection when running AI coding agents, offering configurable isolation without requiring it for basic operations.