sandbox_run
Run the Mobile Workspace edit loop from a headless MCP client. Ships a phone-authored React Native / Expo source tree to its selected remote development device, runs the selected Codex / Claude Code / OpenCode CLI (or that device's saved primary runner) there, and returns an EditPlan-shaped diff....
This record as markdown: /tools/io-github-kivanccakmak-yaver/sandbox-run.md
What sandbox_run does on Yaver
AI agents invoke sandbox_run to trigger actions in Yaver. What it does depends on the arguments the agent supplies, and its effects often reach beyond the immediate call: builds kicked off, notifications sent, workflows started.
| Parameter | Type | Required | Description |
|---|---|---|---|
mode | string | — | Optional OpenCode agent mode such as build or plan. |
files | array | Yes | Phone sandbox files as {path, content}. Paths are posix-relative and may not escape the project root. |
model | string | — | Optional provider/model override. Empty uses this device's saved primary OpenCode model, then OpenCode's configured default. |
prompt | string | Yes | Requested change to make in the sandbox source tree. |
runner | string | — | Optional runner. Empty uses the selected box's saved primary runner, then OpenCode for compatibility. |
schema | object | — | Optional phone-project backend schema context. |
provider | string | — | Optional provider label retained with the selection; credentials remain on the runner. |
device_id | string | — | Optional owned Yaver device id/name/alias to run OpenCode on. Empty = this machine. |
framework | string | — | Framework label for prompting, default React Native (Expo). |
timeoutMs | integer | — | Runner timeout in milliseconds, default 180000, max 600000. |
Parameters from the server's own tool schema.
Why sandbox_run is rated High
Executes arbitrary code on remote devices via mobile workspace; effects depend on source tree content.
From the tool's definition Run...ships...source tree to...remote development device, runs...CLI...returns...diff
Risk signalsAccepts file system path (files[].path) · Accepts raw HTML/template content (files[].content) · High parameter count (12 properties)
Attacks that exploit this kind of access
The rule that runs sandbox_run safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Yaver, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For sandbox_run, this is the rule to start with:
sandbox_run stays usable, but rate-capped: a runaway agent can't fire it dozens of times a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Yaver, apply this rule, and every sandbox_run call is checked against it from then on.
Questions about sandbox_run
Run the Mobile Workspace edit loop from a headless MCP client. Ships a phone-authored React Native / Expo source tree to its selected remote development device, runs the selected Codex / Claude Code / OpenCode CLI (or that device's saved primary runner) there, and returns an EditPlan-shaped diff. Runner credentials stay on the box. The sandbox_run name is retained for API compatibility; it does not claim container isolation. It is categorised as a Execute tool in the Yaver MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.
sandbox_run accepts 10 parameters: mode, files, model, prompt, runner, schema, provider, device_id, framework, timeoutMs. Required: files, prompt. The full parameter table on this page comes from the server's own tool schema.
Register the Yaver MCP server in PolicyLayer and add a rule for sandbox_run: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Yaver. Nothing to install.
sandbox_run is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.
Yes. Add a rate_limit block to the sandbox_run rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for sandbox_run. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
sandbox_run is provided by the Yaver MCP server (yaver-cli). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Yaver, and thousands of servers like it.
Across the catalogue