Sessionboxer

Agents that don't ask

Inside the box the agent runs with all permissions granted. It does not stop to ask whether it may run a command, edit a file or install a package; it just does the work and reports. That is safe because the container is the boundary, not a list of allowed commands.

An opened turn in the chat: numbered LLM calls, Read and Execute tool rows marked completed, and a screenshot the agent took of Firefox shown inline
Open a turn and every command, edit and screenshot is there, each marked completed; none of them waited for a click.

Things you can do with it

Hand over a long task and walk away

"Upgrade the project to Vite 8, fix what breaks, run the tests." The agent runs the install, the build and the test suite as many times as it needs without waiting for you.

Let it use the system

It can apt-get, start services, write to /etc and reboot processes inside the box. Nothing of that touches the host.

Run it from a phone

Because no prompt blocks the turn, you can send a task from your phone and read the result later instead of tapping Allow every minute.

Schedule it

Scheduled tasks would be useless if each run stopped at a permission dialog. In the box they run to the end.

How it works

The agent runs inside the Sandbox container, not on the host, so there is no remote tool layer to escape from and the container is the blast radius. Claude Code runs through claude-agent-acp, Codex through codex-acp and Devin through devin acp, all with permissions granted. Tokens are handed only to the containers of sessions that use that agent and are never stored in snapshots.

Standing instructions from Global settings are given to the agent on every start, and the project's own CLAUDE.md or AGENTS.md apply as usual. You still keep the Stop button, and every turn ends with a snapshot you can go back to.

A running turn folded into one line reading Working, 5 messages so far, 0:04, next to a still-connecting Desktop pane
While it works, the turn is one line. You are not asked anything.

Compared with other products

SessionboxerDevinCursor Cloud AgentsCodex cloudClaude Code on the webOpenHandsT3 Code
Agent runs without permission prompts✓, inside the box✓✓✓✓✓your choice
Isolated sandbox per sessionDocker, or a Windows/macOS VMVMVMcontainerVMDocker✗ (your machine)
Runs on your machine or your server✓✗✗✗✗✓✓

Hosted agents run without prompts too, because they also work in a machine of their own. On your laptop, Claude Code and Codex ask before most commands unless you switch permission checks off, and their docs recommend doing that only inside a sandbox. Sessionboxer is that sandbox, on your hardware.

T3 Code runs the same CLIs on your machine, so the choice between prompts and full access is yours, with your files at stake.

Based on each product's public documentation, September 2026; ✓ = offered, ✗ = not offered, — = not found in the docs. Corrections welcome as an issue.