Sandboxes
Helios agents run in isolated cloud sandboxes with a shell, a filesystem, code execution, web access, and the Library mounted read-only or read-write.
Every Helios agent runs inside its own sandbox - an isolated cloud computer, provisioned per chat or per workflow run. Nothing is shared between sandboxes.
This is what separates an agent from a chatbot. It doesn't describe the work; it does the work, on a machine, with tools.
What's inside
A shell and a filesystem. The agent can run commands, read, write, and edit files, and search across them.
Code execution. The default environment is Debian with a build toolchain, git, jq, and a
JavaScript / TypeScript runtime. The agent installs what else it needs. You can also build your own
environment from a Dockerfile.
Web access. The agent can search the web and scrape a URL into clean markdown.
Your tools. Integrations (the full API of each connected service), databases, and any attached MCP servers.
Files
The sandbox filesystem belongs to one run. When the run ends, the filesystem is discarded.
Shared files come from the Library. Helios mounts the Library folders the
run may see under ~/context. The agent reads them from disk. Edits under ~/context are staged as
a proposed change that a person approves or discards. Nothing reaches the Library without approval.
Agents are told to use $TMPDIR for scratch work. See context for what
carries between runs.
Lifetime
A sandbox stays alive while the agent is active and shuts down after a period of inactivity, roughly fifteen minutes. The next message in a chat or the next run of a workflow gets a fresh sandbox with the same Library mounts.
Workflow runs have a hard 30-minute execution limit. See runs and outputs.
Isolation and credentials
Sandboxes start with outbound network access closed. Helios opens access to specific hosts only as the agent's task requires, and injects the necessary authentication at the network layer.
This is the important part: the agent never holds your credentials. When it calls the GitHub API or clones a pinned repository, Helios attaches a short-lived, narrowly scoped token to the outbound request. Nothing readable as a secret exists inside the sandbox for a prompt injection to exfiltrate.
Your secrets are envelope-encrypted at rest and are never passed into the agent's context.
Database access is deliberately narrow
The agent reaches your databases through a dedicated tool. The credentials stay with Helios. Queries run read-only, with a statement timeout and a row limit. See databases and database security for how to bound this further on your side.
Last updated on
Runs and outputs
Every workflow execution is a run: a full agent transcript, a structured result, and a status you can act on.
Context
Helios agents start each run in a fresh sandbox. The Library carries files between runs, and only approved changes reach it. Helios also records how an agent used an API before.