newspaperPress Guidelines
Pricing
Blog
Downloaddownload

Explore our next generation products

See overview

Products

antigravityAntigravity 2.0terminalAntigravity CLIcodeAntigravity IDEsdkAntigravity SDK

Built for developers in the agent-first era

See overview
EnterpriseFrontendFullstackScienceMarketer

Everything you need to stay up-to-date and get help

Documentationkeyboard_arrow_rightChangelogSupportPressReleases

Explore our next generation products

See overview

Products

antigravityAntigravity 2.0terminalAntigravity CLIcodeAntigravity IDEsdkAntigravity SDK

Built for developers in the agent-first era

See overview
EnterpriseFrontendFullstackScienceMarketer
Pricing
Blog

Everything you need to stay up-to-date and get help

Documentationkeyboard_arrow_rightChangelogSupportPressReleases
Home
Antigravity 2.0v2.3.1keyboard_arrow_right
Overview
Getting Started
Build with Google
Feature Overview
Models
Projects
Settingskeyboard_arrow_right
Overview
Agent Settings
Artifact Review
Customizationskeyboard_arrow_right
MCP
Skills
Rules
Plugins
Hooks
Sidecars
Agent Capabilitieskeyboard_arrow_right
Permissions
Subagents
Artifactskeyboard_arrow_right
Overview
Plan
Walkthrough
Screenshots
Antigravity CLIv1.1.5keyboard_arrow_right
Overview
Getting Started
Installation & Auth
Tutorial
Using AGY CLI
Features
Gemini Migration
Prompting
Artifactskeyboard_arrow_right
Overview
Conversations
Agent Capabilitieskeyboard_arrow_right
Choose an execution mode
Subagents
Sandbox
Permissions
Projects
Settingskeyboard_arrow_right
Overview
AI Credits
Customizationskeyboard_arrow_right
MCP
Plugins & Skills
Status Line
Window Title
Commandskeyboard_arrow_right
Agents (/agents)
Code Search (/codesearch)
AI Credits (/credits)
Diff (/diff)
Permissions (/permissions)
Resume (/resume)
Status Line (/statusline)
Window Title (/title)
Model Quotas (/usage, /quota)
Best Practices
Troubleshooting
Reference
Antigravity SDKv0.1.7keyboard_arrow_right
Overview + Quick Start
Customizationskeyboard_arrow_right
MCP
Antigravity IDEv2.1.1keyboard_arrow_right
Overview
Getting Started
Featureskeyboard_arrow_right
Tab
Side Panel
Review Changes
Artifactskeyboard_arrow_right
Plan
Walkthrough
Screenshots
Browser Recordings
Browserkeyboard_arrow_right
Overview
Allowlist / Denylist
Separate Chrome Profile
Customizationskeyboard_arrow_right
MCP
Skills
Rules
Workflows
Plugins
Hooks
Settings
Migrationkeyboard_arrow_right
Firebase Studio Migration
Enterprise
Plans
FAQ
  • side_navigation
  • Antigravity CLI
  • >
  • Agent Capabilities
  • >
  • Sandbox

Sandboxlink

Enforce native operating system process isolation, manage execution containment boundaries, and protect your local workstation.

The security modellink

Because autonomous development agents run local terminal commands, edit source codes, and execute tests directly in your workspace, maintaining a secure workstation environment is critical. Antigravity CLI integrates a native Terminal Sandbox to restrict destructive shell operations or unauthorized remote network calls.

Native OS containmentlink

Unlike heavy virtual containers or isolated virtual machines that slow down execution speeds, Antigravity uses lightweight, native operating system kernel utilities to create secure process rings with zero execution overhead:
Operating SystemSandboxing UtilitySecurity Characteristics
LinuxnsjailOpen-source process isolator utilizing kernel namespaces and cgroups to confine CPU, memory, and path visibility.
macOSsandbox-execNative system tool enforcing policy profiles that restrict absolute filesystem access and raw TCP queries.
WindowsAppContainerDesktop security containment ring isolating filesystem permissions and registry visibility.

Activating the sandboxlink

You configure the sandbox directly inside your global preferences:
text
~/.gemini/antigravity-cli/settings.json

Sandbox configurationslink

Add the sandboxing toggle to your settings profile:
json
{
  "enableTerminalSandbox": true
}
  • enableTerminalSandbox (boolean, default: false): Restricts all local execution commands launched by agents to OS containment rings.

Interactive approvals with sandboxlink

When the agent attempts to run a terminal tool or shell command, the TUI prompt block adapts dynamically based on your sandboxing state:
  • When Sandbox is Enabled: The prompt panel offers a temporary escape option:
    Do you want to proceed?
    1. Yes
    2. Yes, and run without sandbox restrictions
    3. No
Choosing Option 2 bypasses the containment barrier exclusively for that single execution run.
  • When Sandbox is Disabled: The prompt lets you force containment for a risky command:
    Do you want to proceed?
    1. Yes
    2. Yes, and run in sandbox
    3. No

See alsolink

  • Permissions Engine: Configure fine-grained allow/deny policy rules.
  • Plugins & Skills: Create your own custom skills slash commands.
  • Settings, Rendering & Keybindings: Customize keyboard hotkeys and buffers.
Background Tasks & Subagents
Settings, Rendering & Keybindings
On this Page
SandboxThe security modelActivating the sandboxInteractive approvals with sandboxSee also