{"id":288,"date":"2026-03-21T22:47:26","date_gmt":"2026-03-21T14:47:26","guid":{"rendered":"https:\/\/pa.yingzhi8.cn\/index.php\/2026\/03\/21\/tools-multi-agent-sandbox-tools\/"},"modified":"2026-03-21T23:08:55","modified_gmt":"2026-03-21T15:08:55","slug":"tools-multi-agent-sandbox-tools","status":"publish","type":"post","link":"https:\/\/pa.yingzhi8.cn\/index.php\/2026\/03\/21\/tools-multi-agent-sandbox-tools\/","title":{"rendered":"\u591a\u667a\u80fd\u4f53\u6c99\u7bb1\u4e0e\u5de5\u5177"},"content":{"rendered":"<h1>\u591a\u667a\u80fd\u4f53\u6c99\u7bb1\u4e0e\u5de5\u5177<\/h1>\n<h1>\u591a\u667a\u80fd\u4f53\u6c99\u7bb1\u4e0e\u5de5\u5177\u914d\u7f6e<\/h1>\n<h2>\u6982\u8ff0<\/h2>\n<p>\u591a\u667a\u80fd\u4f53\u8bbe\u7f6e\u4e2d\u7684\u6bcf\u4e2a\u667a\u80fd\u4f53\u73b0\u5728\u53ef\u4ee5\u62e5\u6709\u81ea\u5df1\u7684\uff1a<\/p>\n<ul>\n<li><strong>\u6c99\u7bb1\u914d\u7f6e<\/strong>\uff08<code>agents.list[].sandbox<\/code> \u8986\u76d6 <code>agents.defaults.sandbox<\/code>\uff09<\/li>\n<li><strong>\u5de5\u5177\u9650\u5236<\/strong>\uff08<code>tools.allow<\/code> \/ <code>tools.deny<\/code>\uff0c\u4ee5\u53ca <code>agents.list[].tools<\/code>\uff09<\/li>\n<\/ul>\n<p>\u8fd9\u5141\u8bb8\u4f60\u8fd0\u884c\u5177\u6709\u4e0d\u540c\u5b89\u5168\u914d\u7f6e\u6587\u4ef6\u7684\u591a\u4e2a\u667a\u80fd\u4f53\uff1a<\/p>\n<ul>\n<li>\u5177\u6709\u5b8c\u5168\u8bbf\u95ee\u6743\u9650\u7684\u4e2a\u4eba\u52a9\u624b<\/li>\n<li>\u5177\u6709\u53d7\u9650\u5de5\u5177\u7684\u5bb6\u5ead\/\u5de5\u4f5c\u667a\u80fd\u4f53<\/li>\n<li>\u5728\u6c99\u7bb1\u4e2d\u8fd0\u884c\u7684\u9762\u5411\u516c\u4f17\u7684\u667a\u80fd\u4f53<\/li>\n<\/ul>\n<p><code>setupCommand<\/code> \u5c5e\u4e8e <code>sandbox.docker<\/code> \u4e0b\uff08\u5168\u5c40\u6216\u6309\u667a\u80fd\u4f53\uff09\uff0c\u5728\u5bb9\u5668\u521b\u5efa\u65f6\u8fd0\u884c\u4e00\u6b21\u3002<\/p>\n<p>\u8ba4\u8bc1\u662f\u6309\u667a\u80fd\u4f53\u7684\uff1a\u6bcf\u4e2a\u667a\u80fd\u4f53\u4ece\u5176\u81ea\u5df1\u7684 <code>agentDir<\/code> \u8ba4\u8bc1\u5b58\u50a8\u8bfb\u53d6\uff1a<\/p>\n<pre><code>~\/.openclaw\/agents\/&lt;agentId&gt;\/agent\/auth-profiles.json\n<\/code><\/pre>\n<p>\u51ed\u8bc1<strong>\u4e0d\u4f1a<\/strong>\u5728\u667a\u80fd\u4f53\u4e4b\u95f4\u5171\u4eab\u3002\u5207\u52ff\u5728\u667a\u80fd\u4f53\u4e4b\u95f4\u91cd\u7528 <code>agentDir<\/code>\u3002<br \/>\n\u5982\u679c\u4f60\u60f3\u5171\u4eab\u51ed\u8bc1\uff0c\u8bf7\u5c06 <code>auth-profiles.json<\/code> \u590d\u5236\u5230\u5176\u4ed6\u667a\u80fd\u4f53\u7684 <code>agentDir<\/code> \u4e2d\u3002<\/p>\n<p>\u6709\u5173\u6c99\u7bb1\u9694\u79bb\u5728\u8fd0\u884c\u65f6\u7684\u884c\u4e3a\uff0c\u8bf7\u53c2\u89c1<a href=\"\/gateway\/sandboxing\">\u6c99\u7bb1\u9694\u79bb<\/a>\u3002<br \/>\n\u6709\u5173\u8c03\u8bd5&#8221;\u4e3a\u4ec0\u4e48\u8fd9\u88ab\u963b\u6b62\u4e86\uff1f&#8221;\uff0c\u8bf7\u53c2\u89c1<a href=\"\/gateway\/sandbox-vs-tool-policy-vs-elevated\">\u6c99\u7bb1 vs \u5de5\u5177\u7b56\u7565 vs \u63d0\u6743<\/a> \u548c <code>openclaw sandbox explain<\/code>\u3002<\/p>\n<hr \/>\n<h2>\u914d\u7f6e\u793a\u4f8b<\/h2>\n<h3>\u793a\u4f8b 1\uff1a\u4e2a\u4eba + \u53d7\u9650\u5bb6\u5ead\u667a\u80fd\u4f53<\/h3>\n<p>&#8220;`json  theme={&#8220;theme&#8221;:{&#8220;light&#8221;:&#8221;min-light&#8221;,&#8221;dark&#8221;:&#8221;min-dark&#8221;}}<br \/>\n{<br \/>\n  &#8220;agents&#8221;: {<br \/>\n    &#8220;list&#8221;: [<br \/>\n      {<br \/>\n        &#8220;id&#8221;: &#8220;main&#8221;,<br \/>\n        &#8220;default&#8221;: true,<br \/>\n        &#8220;name&#8221;: &#8220;Personal Assistant&#8221;,<br \/>\n        &#8220;workspace&#8221;: &#8220;~\/.openclaw\/workspace&#8221;,<br \/>\n        &#8220;sandbox&#8221;: { &#8220;mode&#8221;: &#8220;off&#8221; }<br \/>\n      },<br \/>\n      {<br \/>\n        &#8220;id&#8221;: &#8220;family&#8221;,<br \/>\n        &#8220;name&#8221;: &#8220;Family Bot&#8221;,<br \/>\n        &#8220;workspace&#8221;: &#8220;~\/.openclaw\/workspace-family&#8221;,<br \/>\n        &#8220;sandbox&#8221;: {<br \/>\n          &#8220;mode&#8221;: &#8220;all&#8221;,<br \/>\n          &#8220;scope&#8221;: &#8220;agent&#8221;<br \/>\n        },<br \/>\n        &#8220;tools&#8221;: {<br \/>\n          &#8220;allow&#8221;: [&#8220;read&#8221;],<br \/>\n          &#8220;deny&#8221;: [&#8220;exec&#8221;, &#8220;write&#8221;, &#8220;edit&#8221;, &#8220;apply_patch&#8221;, &#8220;process&#8221;, &#8220;browser&#8221;]<br \/>\n        }<br \/>\n      }<br \/>\n    ]<br \/>\n  },<br \/>\n  &#8220;bindings&#8221;: [<br \/>\n    {<br \/>\n      &#8220;agentId&#8221;: &#8220;family&#8221;,<br \/>\n      &#8220;match&#8221;: {<br \/>\n        &#8220;provider&#8221;: &#8220;whatsapp&#8221;,<br \/>\n        &#8220;accountId&#8221;: &#8220;*&#8221;,<br \/>\n        &#8220;peer&#8221;: {<br \/>\n          &#8220;kind&#8221;: &#8220;group&#8221;,<br \/>\n          &#8220;id&#8221;: &#8220;120363424282127706@g.us&#8221;<br \/>\n        }<br \/>\n      }<br \/>\n    }<br \/>\n  ]<br \/>\n}<\/p>\n<pre><code>\n**\u7ed3\u679c\uff1a**\n\n* `main` \u667a\u80fd\u4f53\uff1a\u5728\u4e3b\u673a\u4e0a\u8fd0\u884c\uff0c\u5b8c\u5168\u5de5\u5177\u8bbf\u95ee\n* `family` \u667a\u80fd\u4f53\uff1a\u5728 Docker \u4e2d\u8fd0\u884c\uff08\u6bcf\u4e2a\u667a\u80fd\u4f53\u4e00\u4e2a\u5bb9\u5668\uff09\uff0c\u4ec5\u6709 `read` \u5de5\u5177\n\n***\n\n### \u793a\u4f8b 2\uff1a\u5177\u6709\u5171\u4eab\u6c99\u7bb1\u7684\u5de5\u4f5c\u667a\u80fd\u4f53\n\n```json  theme={&quot;theme&quot;:{&quot;light&quot;:&quot;min-light&quot;,&quot;dark&quot;:&quot;min-dark&quot;}}\n{\n  &quot;agents&quot;: {\n    &quot;list&quot;: [\n      {\n        &quot;id&quot;: &quot;personal&quot;,\n        &quot;workspace&quot;: &quot;~\/.openclaw\/workspace-personal&quot;,\n        &quot;sandbox&quot;: { &quot;mode&quot;: &quot;off&quot; }\n      },\n      {\n        &quot;id&quot;: &quot;work&quot;,\n        &quot;workspace&quot;: &quot;~\/.openclaw\/workspace-work&quot;,\n        &quot;sandbox&quot;: {\n          &quot;mode&quot;: &quot;all&quot;,\n          &quot;scope&quot;: &quot;shared&quot;,\n          &quot;workspaceRoot&quot;: &quot;\/tmp\/work-sandboxes&quot;\n        },\n        &quot;tools&quot;: {\n          &quot;allow&quot;: [&quot;read&quot;, &quot;write&quot;, &quot;apply_patch&quot;, &quot;exec&quot;],\n          &quot;deny&quot;: [&quot;browser&quot;, &quot;gateway&quot;, &quot;discord&quot;]\n        }\n      }\n    ]\n  }\n}\n<\/code><\/pre>\n<hr \/>\n<h3>\u793a\u4f8b 2b\uff1a\u5168\u5c40\u7f16\u7801\u914d\u7f6e\u6587\u4ef6 + \u4ec5\u6d88\u606f\u667a\u80fd\u4f53<\/h3>\n<p>&#8220;`json  theme={&#8220;theme&#8221;:{&#8220;light&#8221;:&#8221;min-light&#8221;,&#8221;dark&#8221;:&#8221;min-dark&#8221;}}<br \/>\n{<br \/>\n  &#8220;tools&#8221;: { &#8220;profile&#8221;: &#8220;coding&#8221; },<br \/>\n  &#8220;agents&#8221;: {<br \/>\n    &#8220;list&#8221;: [<br \/>\n      {<br \/>\n        &#8220;id&#8221;: &#8220;support&#8221;,<br \/>\n        &#8220;tools&#8221;: { &#8220;profile&#8221;: &#8220;messaging&#8221;, &#8220;allow&#8221;: [&#8220;slack&#8221;] }<br \/>\n      }<br \/>\n    ]<br \/>\n  }<br \/>\n}<\/p>\n<pre><code>\n**\u7ed3\u679c\uff1a**\n\n* \u9ed8\u8ba4\u667a\u80fd\u4f53\u83b7\u5f97\u7f16\u7801\u5de5\u5177\n* `support` \u667a\u80fd\u4f53\u4ec5\u7528\u4e8e\u6d88\u606f\uff08+ Slack \u5de5\u5177\uff09\n\n***\n\n### \u793a\u4f8b 3\uff1a\u6bcf\u4e2a\u667a\u80fd\u4f53\u4e0d\u540c\u7684\u6c99\u7bb1\u6a21\u5f0f\n\n```json  theme={&quot;theme&quot;:{&quot;light&quot;:&quot;min-light&quot;,&quot;dark&quot;:&quot;min-dark&quot;}}\n{\n  &quot;agents&quot;: {\n    &quot;defaults&quot;: {\n      &quot;sandbox&quot;: {\n        &quot;mode&quot;: &quot;non-main&quot;, \/\/ \u5168\u5c40\u9ed8\u8ba4\n        &quot;scope&quot;: &quot;session&quot;\n      }\n    },\n    &quot;list&quot;: [\n      {\n        &quot;id&quot;: &quot;main&quot;,\n        &quot;workspace&quot;: &quot;~\/.openclaw\/workspace&quot;,\n        &quot;sandbox&quot;: {\n          &quot;mode&quot;: &quot;off&quot; \/\/ \u8986\u76d6\uff1amain \u6c38\u4e0d\u6c99\u7bb1\u9694\u79bb\n        }\n      },\n      {\n        &quot;id&quot;: &quot;public&quot;,\n        &quot;workspace&quot;: &quot;~\/.openclaw\/workspace-public&quot;,\n        &quot;sandbox&quot;: {\n          &quot;mode&quot;: &quot;all&quot;, \/\/ \u8986\u76d6\uff1apublic \u59cb\u7ec8\u6c99\u7bb1\u9694\u79bb\n          &quot;scope&quot;: &quot;agent&quot;\n        },\n        &quot;tools&quot;: {\n          &quot;allow&quot;: [&quot;read&quot;],\n          &quot;deny&quot;: [&quot;exec&quot;, &quot;write&quot;, &quot;edit&quot;, &quot;apply_patch&quot;]\n        }\n      }\n    ]\n  }\n}\n<\/code><\/pre>\n<hr \/>\n<h2>\u914d\u7f6e\u4f18\u5148\u7ea7<\/h2>\n<p>\u5f53\u5168\u5c40\uff08<code>agents.defaults.*<\/code>\uff09\u548c\u667a\u80fd\u4f53\u7279\u5b9a\uff08<code>agents.list[].*<\/code>\uff09\u914d\u7f6e\u540c\u65f6\u5b58\u5728\u65f6\uff1a<\/p>\n<h3>\u6c99\u7bb1\u914d\u7f6e<\/h3>\n<p>\u667a\u80fd\u4f53\u7279\u5b9a\u8bbe\u7f6e\u8986\u76d6\u5168\u5c40\uff1a<\/p>\n<pre><code>agents.list[].sandbox.mode &gt; agents.defaults.sandbox.mode\nagents.list[].sandbox.scope &gt; agents.defaults.sandbox.scope\nagents.list[].sandbox.workspaceRoot &gt; agents.defaults.sandbox.workspaceRoot\nagents.list[].sandbox.workspaceAccess &gt; agents.defaults.sandbox.workspaceAccess\nagents.list[].sandbox.docker.* &gt; agents.defaults.sandbox.docker.*\nagents.list[].sandbox.browser.* &gt; agents.defaults.sandbox.browser.*\nagents.list[].sandbox.prune.* &gt; agents.defaults.sandbox.prune.*\n<\/code><\/pre>\n<p><strong>\u6ce8\u610f\u4e8b\u9879\uff1a<\/strong><\/p>\n<ul>\n<li><code>agents.list[].sandbox.{docker,browser,prune}.*<\/code> \u4e3a\u8be5\u667a\u80fd\u4f53\u8986\u76d6 <code>agents.defaults.sandbox.{docker,browser,prune}.*<\/code>\uff08\u5f53\u6c99\u7bb1 scope \u89e3\u6790\u4e3a <code>\"shared\"<\/code> \u65f6\u5ffd\u7565\uff09\u3002<\/li>\n<\/ul>\n<h3>\u5de5\u5177\u9650\u5236<\/h3>\n<p>\u8fc7\u6ee4\u987a\u5e8f\u662f\uff1a<\/p>\n<ol>\n<li><strong>\u5de5\u5177\u914d\u7f6e\u6587\u4ef6<\/strong>\uff08<code>tools.profile<\/code> \u6216 <code>agents.list[].tools.profile<\/code>\uff09<\/li>\n<li><strong>\u63d0\u4f9b\u5546\u5de5\u5177\u914d\u7f6e\u6587\u4ef6<\/strong>\uff08<code>tools.byProvider[provider].profile<\/code> \u6216 <code>agents.list[].tools.byProvider[provider].profile<\/code>\uff09<\/li>\n<li><strong>\u5168\u5c40\u5de5\u5177\u7b56\u7565<\/strong>\uff08<code>tools.allow<\/code> \/ <code>tools.deny<\/code>\uff09<\/li>\n<li><strong>\u63d0\u4f9b\u5546\u5de5\u5177\u7b56\u7565<\/strong>\uff08<code>tools.byProvider[provider].allow\/deny<\/code>\uff09<\/li>\n<li><strong>\u667a\u80fd\u4f53\u7279\u5b9a\u5de5\u5177\u7b56\u7565<\/strong>\uff08<code>agents.list[].tools.allow\/deny<\/code>\uff09<\/li>\n<li><strong>\u667a\u80fd\u4f53\u63d0\u4f9b\u5546\u7b56\u7565<\/strong>\uff08<code>agents.list[].tools.byProvider[provider].allow\/deny<\/code>\uff09<\/li>\n<li><strong>\u6c99\u7bb1\u5de5\u5177\u7b56\u7565<\/strong>\uff08<code>tools.sandbox.tools<\/code> \u6216 <code>agents.list[].tools.sandbox.tools<\/code>\uff09<\/li>\n<li><strong>\u5b50\u667a\u80fd\u4f53\u5de5\u5177\u7b56\u7565<\/strong>\uff08<code>tools.subagents.tools<\/code>\uff0c\u5982\u9002\u7528\uff09<\/li>\n<\/ol>\n<p>\u6bcf\u4e2a\u7ea7\u522b\u53ef\u4ee5\u8fdb\u4e00\u6b65\u9650\u5236\u5de5\u5177\uff0c\u4f46\u4e0d\u80fd\u6062\u590d\u4e4b\u524d\u7ea7\u522b\u62d2\u7edd\u7684\u5de5\u5177\u3002<br \/>\n\u5982\u679c\u8bbe\u7f6e\u4e86 <code>agents.list[].tools.sandbox.tools<\/code>\uff0c\u5b83\u5c06\u66ff\u6362\u8be5\u667a\u80fd\u4f53\u7684 <code>tools.sandbox.tools<\/code>\u3002<br \/>\n\u5982\u679c\u8bbe\u7f6e\u4e86 <code>agents.list[].tools.profile<\/code>\uff0c\u5b83\u5c06\u8986\u76d6\u8be5\u667a\u80fd\u4f53\u7684 <code>tools.profile<\/code>\u3002<br \/>\n\u63d0\u4f9b\u5546\u5de5\u5177\u952e\u63a5\u53d7 <code>provider<\/code>\uff08\u4f8b\u5982 <code>google-antigravity<\/code>\uff09\u6216 <code>provider\/model<\/code>\uff08\u4f8b\u5982 <code>openai\/gpt-5.2<\/code>\uff09\u3002<\/p>\n<h3>\u5de5\u5177\u7ec4\uff08\u7b80\u5199\uff09<\/h3>\n<p>\u5de5\u5177\u7b56\u7565\uff08\u5168\u5c40\u3001\u667a\u80fd\u4f53\u3001\u6c99\u7bb1\uff09\u652f\u6301 <code>group:*<\/code> \u6761\u76ee\uff0c\u53ef\u6269\u5c55\u4e3a\u591a\u4e2a\u5177\u4f53\u5de5\u5177\uff1a<\/p>\n<ul>\n<li><code>group:runtime<\/code>\uff1a<code>exec<\/code>\u3001<code>bash<\/code>\u3001<code>process<\/code><\/li>\n<li><code>group:fs<\/code>\uff1a<code>read<\/code>\u3001<code>write<\/code>\u3001<code>edit<\/code>\u3001<code>apply_patch<\/code><\/li>\n<li><code>group:sessions<\/code>\uff1a<code>sessions_list<\/code>\u3001<code>sessions_history<\/code>\u3001<code>sessions_send<\/code>\u3001<code>sessions_spawn<\/code>\u3001<code>session_status<\/code><\/li>\n<li><code>group:memory<\/code>\uff1a<code>memory_search<\/code>\u3001<code>memory_get<\/code><\/li>\n<li><code>group:ui<\/code>\uff1a<code>browser<\/code>\u3001<code>canvas<\/code><\/li>\n<li><code>group:automation<\/code>\uff1a<code>cron<\/code>\u3001<code>gateway<\/code><\/li>\n<li><code>group:messaging<\/code>\uff1a<code>message<\/code><\/li>\n<li><code>group:nodes<\/code>\uff1a<code>nodes<\/code><\/li>\n<li><code>group:openclaw<\/code>\uff1a\u6240\u6709\u5185\u7f6e OpenClaw \u5de5\u5177\uff08\u4e0d\u5305\u62ec\u63d0\u4f9b\u5546\u63d2\u4ef6\uff09<\/li>\n<\/ul>\n<h3>\u63d0\u6743\u6a21\u5f0f<\/h3>\n<p><code>tools.elevated<\/code> \u662f\u5168\u5c40\u57fa\u7ebf\uff08\u57fa\u4e8e\u53d1\u9001\u8005\u7684\u5141\u8bb8\u5217\u8868\uff09\u3002<code>agents.list[].tools.elevated<\/code> \u53ef\u4ee5\u4e3a\u7279\u5b9a\u667a\u80fd\u4f53\u8fdb\u4e00\u6b65\u9650\u5236\u63d0\u6743\uff08\u4e24\u8005\u90fd\u5fc5\u987b\u5141\u8bb8\uff09\u3002<\/p>\n<p>\u7f13\u89e3\u6a21\u5f0f\uff1a<\/p>\n<ul>\n<li>\u4e3a\u4e0d\u53d7\u4fe1\u4efb\u7684\u667a\u80fd\u4f53\u62d2\u7edd <code>exec<\/code>\uff08<code>agents.list[].tools.deny: [\"exec\"]<\/code>\uff09<\/li>\n<li>\u907f\u514d\u5c06\u53d1\u9001\u8005\u52a0\u5165\u5141\u8bb8\u5217\u8868\u540e\u8def\u7531\u5230\u53d7\u9650\u667a\u80fd\u4f53<\/li>\n<li>\u5982\u679c\u4f60\u53ea\u60f3\u8981\u6c99\u7bb1\u9694\u79bb\u6267\u884c\uff0c\u5168\u5c40\u7981\u7528\u63d0\u6743\uff08<code>tools.elevated.enabled: false<\/code>\uff09<\/li>\n<li>\u4e3a\u654f\u611f\u914d\u7f6e\u6587\u4ef6\u6309\u667a\u80fd\u4f53\u7981\u7528\u63d0\u6743\uff08<code>agents.list[].tools.elevated.enabled: false<\/code>\uff09<\/li>\n<\/ul>\n<hr \/>\n<h2>\u4ece\u5355\u667a\u80fd\u4f53\u8fc1\u79fb<\/h2>\n<p><strong>\u4e4b\u524d\uff08\u5355\u667a\u80fd\u4f53\uff09\uff1a<\/strong><\/p>\n<p>&#8220;`json  theme={&#8220;theme&#8221;:{&#8220;light&#8221;:&#8221;min-light&#8221;,&#8221;dark&#8221;:&#8221;min-dark&#8221;}}<br \/>\n{<br \/>\n  &#8220;agents&#8221;: {<br \/>\n    &#8220;defaults&#8221;: {<br \/>\n      &#8220;workspace&#8221;: &#8220;~\/.openclaw\/workspace&#8221;,<br \/>\n      &#8220;sandbox&#8221;: {<br \/>\n        &#8220;mode&#8221;: &#8220;non-main&#8221;<br \/>\n      }<br \/>\n    }<br \/>\n  },<br \/>\n  &#8220;tools&#8221;: {<br \/>\n    &#8220;sandbox&#8221;: {<br \/>\n      &#8220;tools&#8221;: {<br \/>\n        &#8220;allow&#8221;: [&#8220;read&#8221;, &#8220;write&#8221;, &#8220;apply_patch&#8221;, &#8220;exec&#8221;],<br \/>\n        &#8220;deny&#8221;: []<br \/>\n      }<br \/>\n    }<br \/>\n  }<br \/>\n}<\/p>\n<pre><code>\n**\u4e4b\u540e\uff08\u5177\u6709\u4e0d\u540c\u914d\u7f6e\u6587\u4ef6\u7684\u591a\u667a\u80fd\u4f53\uff09\uff1a**\n\n```json  theme={&quot;theme&quot;:{&quot;light&quot;:&quot;min-light&quot;,&quot;dark&quot;:&quot;min-dark&quot;}}\n{\n  &quot;agents&quot;: {\n    &quot;list&quot;: [\n      {\n        &quot;id&quot;: &quot;main&quot;,\n        &quot;default&quot;: true,\n        &quot;workspace&quot;: &quot;~\/.openclaw\/workspace&quot;,\n        &quot;sandbox&quot;: { &quot;mode&quot;: &quot;off&quot; }\n      }\n    ]\n  }\n}\n<\/code><\/pre>\n<p>\u65e7\u7248 <code>agent.*<\/code> \u914d\u7f6e\u7531 <code>openclaw doctor<\/code> \u8fc1\u79fb\uff1b\u4eca\u540e\u8bf7\u4f18\u5148\u4f7f\u7528 <code>agents.defaults<\/code> + <code>agents.list<\/code>\u3002<\/p>\n<hr \/>\n<h2>\u5de5\u5177\u9650\u5236\u793a\u4f8b<\/h2>\n<h3>\u53ea\u8bfb\u667a\u80fd\u4f53<\/h3>\n<p>&#8220;`json  theme={&#8220;theme&#8221;:{&#8220;light&#8221;:&#8221;min-light&#8221;,&#8221;dark&#8221;:&#8221;min-dark&#8221;}}<br \/>\n{<br \/>\n  &#8220;tools&#8221;: {<br \/>\n    &#8220;allow&#8221;: [&#8220;read&#8221;],<br \/>\n    &#8220;deny&#8221;: [&#8220;exec&#8221;, &#8220;write&#8221;, &#8220;edit&#8221;, &#8220;apply_patch&#8221;, &#8220;process&#8221;]<br \/>\n  }<br \/>\n}<\/p>\n<pre><code>\n### \u5b89\u5168\u6267\u884c\u667a\u80fd\u4f53\uff08\u65e0\u6587\u4ef6\u4fee\u6539\uff09\n\n```json  theme={&quot;theme&quot;:{&quot;light&quot;:&quot;min-light&quot;,&quot;dark&quot;:&quot;min-dark&quot;}}\n{\n  &quot;tools&quot;: {\n    &quot;allow&quot;: [&quot;read&quot;, &quot;exec&quot;, &quot;process&quot;],\n    &quot;deny&quot;: [&quot;write&quot;, &quot;edit&quot;, &quot;apply_patch&quot;, &quot;browser&quot;, &quot;gateway&quot;]\n  }\n}\n<\/code><\/pre>\n<h3>\u4ec5\u901a\u4fe1\u667a\u80fd\u4f53<\/h3>\n<p><code>json  theme={\"theme\":{\"light\":\"min-light\",\"dark\":\"min-dark\"}}<br \/>\n{<br \/>\n  \"tools\": {<br \/>\n    \"allow\": [\"sessions_list\", \"sessions_send\", \"sessions_history\", \"session_status\"],<br \/>\n    \"deny\": [\"exec\", \"write\", \"edit\", \"apply_patch\", \"read\", \"browser\"]<br \/>\n  }<br \/>\n}<\/code><\/p>\n<hr \/>\n<h2>\u5e38\u89c1\u9677\u9631\uff1a&#8221;non-main&#8221;<\/h2>\n<p><code>agents.defaults.sandbox.mode: \"non-main\"<\/code> \u57fa\u4e8e <code>session.mainKey<\/code>\uff08\u9ed8\u8ba4 <code>\"main\"<\/code>\uff09\uff0c<br \/>\n\u800c\u4e0d\u662f\u667a\u80fd\u4f53 id\u3002\u7fa4\u7ec4\/\u6e20\u9053\u4f1a\u8bdd\u59cb\u7ec8\u83b7\u5f97\u81ea\u5df1\u7684\u952e\uff0c\u56e0\u6b64\u5b83\u4eec<br \/>\n\u88ab\u89c6\u4e3a\u975e main \u5e76\u5c06\u88ab\u6c99\u7bb1\u9694\u79bb\u3002\u5982\u679c\u4f60\u5e0c\u671b\u667a\u80fd\u4f53\u6c38\u4e0d<br \/>\n\u6c99\u7bb1\u9694\u79bb\uff0c\u8bf7\u8bbe\u7f6e <code>agents.list[].sandbox.mode: \"off\"<\/code>\u3002<\/p>\n<hr \/>\n<h2>\u6d4b\u8bd5<\/h2>\n<p>\u914d\u7f6e\u591a\u667a\u80fd\u4f53\u6c99\u7bb1\u548c\u5de5\u5177\u540e\uff1a<\/p>\n<ol>\n<li><strong>\u68c0\u67e5\u667a\u80fd\u4f53\u89e3\u6790\uff1a<\/strong><\/li>\n<\/ol>\n<p><code>exec  theme={\"theme\":{\"light\":\"min-light\",\"dark\":\"min-dark\"}}<br \/>\n   openclaw agents list --bindings<\/code><\/p>\n<ol start=\"2\">\n<li><strong>\u9a8c\u8bc1\u6c99\u7bb1\u5bb9\u5668\uff1a<\/strong><\/li>\n<\/ol>\n<p><code>exec  theme={\"theme\":{\"light\":\"min-light\",\"dark\":\"min-dark\"}}<br \/>\n   docker ps --filter \"name=openclaw-sbx-\"<\/code><\/p>\n<ol start=\"3\">\n<li>\n<p><strong>\u6d4b\u8bd5\u5de5\u5177\u9650\u5236\uff1a<\/strong><br \/>\n   * \u53d1\u9001\u9700\u8981\u53d7\u9650\u5de5\u5177\u7684\u6d88\u606f<br \/>\n   * \u9a8c\u8bc1\u667a\u80fd\u4f53\u65e0\u6cd5\u4f7f\u7528\u88ab\u62d2\u7edd\u7684\u5de5\u5177<\/p>\n<\/li>\n<li>\n<p><strong>\u76d1\u63a7\u65e5\u5fd7\uff1a<\/strong><br \/>\n   <code>exec  theme={\"theme\":{\"light\":\"min-light\",\"dark\":\"min-dark\"}}<br \/>\n   tail -f \"${OPENCLAW_STATE_DIR:-$HOME\/.openclaw}\/logs\/gateway.log\" | grep -E \"routing|sandbox|tools\"<\/code><\/p>\n<\/li>\n<\/ol>\n<hr \/>\n<h2>\u6545\u969c\u6392\u9664<\/h2>\n<h3>\u5c3d\u7ba1\u8bbe\u7f6e\u4e86 <code>mode: \"all\"<\/code> \u4f46\u667a\u80fd\u4f53\u672a\u88ab\u6c99\u7bb1\u9694\u79bb<\/h3>\n<ul>\n<li>\u68c0\u67e5\u662f\u5426\u6709\u5168\u5c40 <code>agents.defaults.sandbox.mode<\/code> \u8986\u76d6\u5b83<\/li>\n<li>\u667a\u80fd\u4f53\u7279\u5b9a\u914d\u7f6e\u4f18\u5148\uff0c\u56e0\u6b64\u8bbe\u7f6e <code>agents.list[].sandbox.mode: \"all\"<\/code><\/li>\n<\/ul>\n<h3>\u5c3d\u7ba1\u6709\u62d2\u7edd\u5217\u8868\u4f46\u5de5\u5177\u4ecd\u7136\u53ef\u7528<\/h3>\n<ul>\n<li>\u68c0\u67e5\u5de5\u5177\u8fc7\u6ee4\u987a\u5e8f\uff1a\u5168\u5c40 \u2192 \u667a\u80fd\u4f53 \u2192 \u6c99\u7bb1 \u2192 \u5b50\u667a\u80fd\u4f53<\/li>\n<li>\u6bcf\u4e2a\u7ea7\u522b\u53ea\u80fd\u8fdb\u4e00\u6b65\u9650\u5236\uff0c\u4e0d\u80fd\u6062\u590d<\/li>\n<li>\u901a\u8fc7\u65e5\u5fd7\u9a8c\u8bc1\uff1a<code>[tools] filtering tools for agent:${agentId}<\/code><\/li>\n<\/ul>\n<h3>\u5bb9\u5668\u672a\u6309\u667a\u80fd\u4f53\u9694\u79bb<\/h3>\n<ul>\n<li>\u5728\u667a\u80fd\u4f53\u7279\u5b9a\u6c99\u7bb1\u914d\u7f6e\u4e2d\u8bbe\u7f6e <code>scope: \"agent\"<\/code><\/li>\n<li>\u9ed8\u8ba4\u662f <code>\"session\"<\/code>\uff0c\u6bcf\u4e2a\u4f1a\u8bdd\u521b\u5efa\u4e00\u4e2a\u5bb9\u5668<\/li>\n<\/ul>\n<hr \/>\n<h2>\u53e6\u8bf7\u53c2\u9605<\/h2>\n<ul>\n<li><a href=\"\/concepts\/multi-agent\">\u591a\u667a\u80fd\u4f53\u8def\u7531<\/a><\/li>\n<li><a href=\"\/gateway\/configuration#agentsdefaults-sandbox\">\u6c99\u7bb1\u914d\u7f6e<\/a><\/li>\n<li><a href=\"\/concepts\/session\">\u4f1a\u8bdd\u7ba1\u7406<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u591a\u667a\u80fd\u4f53\u6c99\u7bb1\u4e0e\u5de5\u5177 \u591a\u667a\u80fd\u4f53\u6c99\u7bb1\u4e0e\u5de5\u5177\u914d\u7f6e \u6982\u8ff0 \u591a\u667a\u80fd\u4f53\u8bbe\u7f6e\u4e2d\u7684\u6bcf\u4e2a\u667a\u80fd\u4f53\u73b0\u5728\u53ef\u4ee5\u62e5\u6709\u81ea\u5df1\u7684\uff1a \u6c99\u7bb1\u914d\u7f6e\uff08a [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-288","post","type-post","status-publish","format-standard","hentry","category-docs"],"_links":{"self":[{"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/posts\/288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/comments?post=288"}],"version-history":[{"count":1,"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/posts\/288\/revisions"}],"predecessor-version":[{"id":583,"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/posts\/288\/revisions\/583"}],"wp:attachment":[{"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/media?parent=288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/categories?post=288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pa.yingzhi8.cn\/index.php\/wp-json\/wp\/v2\/tags?post=288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}