google-gemini/gemini-cli · error · Error

Tool sandboxing is not yet implemented.

Error message

Tool sandboxing is not yet implemented.

What it means

LocalSandboxManager is a placeholder implementation of SandboxManager that runs commands without sandboxing. Its prepareCommand is a stub that unconditionally throws, signaling that per-tool sandboxing has not been implemented in the local (non-sandboxed) manager. Callers should use the real sandboxed manager or avoid requesting a sandboxed command here.

Solutions

  1. Enable a real sandbox (e.g. --sandbox docker/lxc or the equivalent settings entry) so a backed SandboxManager is used.
  2. Route the command through non-sandboxed execution if sandboxing is not required.
  3. Wait for/upgrade to a version that implements tool sandboxing in LocalSandboxManager.

Example fix

// before
gemini  # default (local manager), calls tool.prepareCommand
// after
gemini --sandbox docker
Defensive patterns

Strategy: try-catch

Validate before calling

if (manager instanceof LocalSandboxManager) {
  throw new Error('tool sandboxing requires a docker/lxc sandbox manager');
}

Try / catch

try {
  const cmd = await manager.prepareCommand(req);
} catch (e) {
  if (e.message.includes('not yet implemented')) {
    // fall back to unsandboxed execution or enable --sandbox docker/lxc
  }
}

Prevention

When it happens

Trigger: Calling prepareCommand on a LocalSandboxManager instance (i.e. requesting a SandboxedCommand while the CLI/core is configured with the local, no-sandbox manager).

Common situations: Enabling a tool-sandboxing feature or code path while running without a configured sandbox backend; using an API that assumes a Docker/LXC-backed SandboxManager but getting the local default.

Related errors


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/4cf8fdb6f41cbca2. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/services/sandboxManager.ts:344

  }

  getWorkspace(): string {
    return this.options?.workspace ?? process.cwd();
  }

  getOptions(): GlobalSandboxOptions | undefined {
    return this.options;
  }
}

/**
 * A SandboxManager implementation that just runs locally (no sandboxing yet).
 */
export class LocalSandboxManager implements SandboxManager {
  constructor(private options?: GlobalSandboxOptions) {}

  async prepareCommand(_req: SandboxRequest): Promise<SandboxedCommand> {
    throw new Error('Tool sandboxing is not yet implemented.');
  }

  isKnownSafeCommand(_args: string[], _cwd?: string): boolean {
    return false;
  }

  isDangerousCommand(_args: string[], _cwd?: string): boolean {
    return false;
  }

  parseDenials(): undefined {
    return undefined;
  }

  getWorkspace(): string {
    return this.options?.workspace ?? process.cwd();
  }

View on GitHub (pinned to 6a466a7e2f)