google-gemini/gemini-cli · error · Error
Tool sandboxing is not yet implemented.
Error message
Tool sandboxing is not yet implemented.
What it means
LocalSandboxManager is a placeholder implementation of SandboxManager that runs commands without sandboxing. Its prepareCommand is a stub that unconditionally throws, signaling that per-tool sandboxing has not been implemented in the local (non-sandboxed) manager. Callers should use the real sandboxed manager or avoid requesting a sandboxed command here.
Solutions
- Enable a real sandbox (e.g. --sandbox docker/lxc or the equivalent settings entry) so a backed SandboxManager is used.
- Route the command through non-sandboxed execution if sandboxing is not required.
- Wait for/upgrade to a version that implements tool sandboxing in LocalSandboxManager.
Example fix
// before gemini # default (local manager), calls tool.prepareCommand // after gemini --sandbox docker
Defensive patterns
Strategy: try-catch
Validate before calling
if (manager instanceof LocalSandboxManager) {
throw new Error('tool sandboxing requires a docker/lxc sandbox manager');
} Try / catch
try {
const cmd = await manager.prepareCommand(req);
} catch (e) {
if (e.message.includes('not yet implemented')) {
// fall back to unsandboxed execution or enable --sandbox docker/lxc
}
} Prevention
- Enable a real sandbox backend before exercising sandboxed tool execution.
- Feature-detect: check the manager type rather than assuming prepareCommand works.
- Track CLI/core release notes for when local tool sandboxing ships.
When it happens
Trigger: Calling prepareCommand on a LocalSandboxManager instance (i.e. requesting a SandboxedCommand while the CLI/core is configured with the local, no-sandbox manager).
Common situations: Enabling a tool-sandboxing feature or code path while running without a configured sandbox backend; using an API that assumes a Docker/LXC-backed SandboxManager but getting the local default.
Related errors
- GEMINI_SANDBOX is true but failed to determine command for…
- Running sandbox from a sensitive host directory
- Access to forbidden path is denied
- AGENT_EXECUTION_BLOCKED
- Cannot build sandbox using installed gemini binary; run…
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/4cf8fdb6f41cbca2.
Report an issue: GitHub.
Appendix: source
Thrown at packages/core/src/services/sandboxManager.ts:344
}
getWorkspace(): string {
return this.options?.workspace ?? process.cwd();
}
getOptions(): GlobalSandboxOptions | undefined {
return this.options;
}
}
/**
* A SandboxManager implementation that just runs locally (no sandboxing yet).
*/
export class LocalSandboxManager implements SandboxManager {
constructor(private options?: GlobalSandboxOptions) {}
async prepareCommand(_req: SandboxRequest): Promise<SandboxedCommand> {
throw new Error('Tool sandboxing is not yet implemented.');
}
isKnownSafeCommand(_args: string[], _cwd?: string): boolean {
return false;
}
isDangerousCommand(_args: string[], _cwd?: string): boolean {
return false;
}
parseDenials(): undefined {
return undefined;
}
getWorkspace(): string {
return this.options?.workspace ?? process.cwd();
}
View on GitHub (pinned to 6a466a7e2f)