The sandbox starts when the work does.

Tusko is an open-source agentic platform you can run yourself. Chat, planning, and lookups answer without a container. An isolated OpenSandbox container spawns on the first write or execute call, and a Steel browser on the first browse.

Self-host Tusko View source on GitHub

BSD 3-Clause. Postgres plus Docker or Kubernetes. Try the hosted app

trace · one chat turn“Create a 6-slide Q3 deck with speaker notes.”

sandboxes 1

sandbox spawn

tier
sandbox
trigger
first write to /workspace this session
call
getOrCreateOpenSandbox
pool
warm · Docker or Kubernetes
quota
1 of 5 live per user (default)
credentials
fail-closed, from env only
idle_ttl
30m, then reaped
Fast lane: runs in the chat process, no container Sandbox lane: isolated OpenSandbox container Span structure follows the product; timings are illustrative.

Two lanes. Only one of them costs a container.

Most of a conversation is talking, planning, and looking things up. Tusko keeps that work in the chat process. A sandbox is allocated the moment a tool has to write or run something, and stays alive for the rest of the session.

Fast lane

In the chat process. No container.

plan_task
A named goal and 3 to 5 milestones, shown inline before anything runs.
search_chunks
Lookups in Utopia, the built-in knowledge graph and long-term memory.
delegate_subagent
Splits larger jobs across Researcher, Coder, and Reviewer roles.
list_files · preview
Reads use getExistingOpenSandbox, so they can never start a container.

Sandbox lane

In an isolated OpenSandbox container, per session.

execute_command
Runs in /workspace. Variables, dataframes, and files persist across turns.
write_file
Office libraries are preinstalled: python-pptx, openpyxl, pandas, python-docx, pypdf.
Steel browser
Navigation, screenshots, and multi-step actions, with a live watch view in the side panel.
warm pool
Docker or Kubernetes keeps the first execution fast. Idle sandboxes are reaped after 30 min.

Full lifecycle, including the Kubernetes warm pool: Sandbox lifecycle and security

What stops the sandbox from being the problem.

Each guardrail below is enforced on the server and documented, with the setting that controls it. Read the source if you would rather check than trust.

  • Fail-closed credentials

    The sandbox service needs OPENSANDBOX_URL and OPENSANDBOX_API_KEY from the environment. Without them, nothing executes. There are no hardcoded keys or fallback gateways.

    OPENSANDBOX_API_KEY Docs: Fail-closed credentials

  • Per-user sandbox quota

    Each user can hold a limited number of live sandboxes. A spawn over the limit returns a 429 quota error.

    MAX_SANDBOXES_PER_USER=5 Docs: Per-user sandbox quota

  • Path safety

    Every file write is confined to /workspace. Path traversal and NUL bytes are rejected, and paths are never interpolated into a shell.

    /workspace Docs: Path safety

  • Outbound fetch checks

    Fetches made on the agent’s behalf pass SSRF checks before they leave the server.

    ssrf Docs: Outbound fetch checks

  • Chat guardrails

    Chat requires an SSO session. Models come from a server-side allowlist. Requests carry at most the last 200 messages and an 8,000-character system prompt.

    CHAT_RATE_LIMIT_MAX=30 Docs: Chat guardrails

  • Idle reaping

    A sandbox with no activity for 30 minutes is reaped. Deleting a chat session never deletes files you downloaded.

    idle_ttl=30m Docs: Idle reaping

What it does once it has a place to work.

  • Office documents

    Decks, spreadsheets, and reports are generated by real code with python-pptx, openpyxl, and python-docx, then previewed and downloaded in chat. PDFs can be parsed and two files compared side by side.

    • .pptx
    • .xlsx
    • .docx
    • PDF parsing
    • compare_files
    run
    sandbox lane
    Chat to artifact
  • Skills and subagents

    Type / to start a skill: presentation, financial model, Word report, security audit, code review. Skills follow the open SKILL.md format. Larger jobs are split across Researcher, Coder, and Reviewer subagents.

    • SKILL.md
    • delegate_subagent
    plan
    fast lane
    run
    sandbox lane
    Skills and subagents
  • Memory and schedules

    Utopia keeps a knowledge graph with dated facts and long-term memory. Tasks can run on a cron schedule, notify you on Telegram, and snapshot the workspace to S3 or MinIO.

    • remember
    • cron
    • Telegram
    • S3 / MinIO
    run
    fast lane
    Knowledge and scheduling

Run it yourself.

Tusko is a Next.js app on Postgres, released under the BSD 3-Clause license. Point it at an OpenSandbox service for execution and a Steel browser for the web. If you leave the sandbox credentials unset, execution stays off instead of falling back to something less safe.

Would rather not host it? Create a hosted account

.env placeholder values
DATABASE_URL=postgres://tusko:…@db:5432/tuskoOPENSANDBOX_URL=http://opensandbox:8080OPENSANDBOX_API_KEY=…MAX_SANDBOXES_PER_USER=5K8S_SANDBOX_ENABLED=falseK8S_SANDBOX_WARM_POOL_SIZE=2