@enclave-vm/browser.
Quick Example
Core Options
Console Limits
Security Level Comparison
All “varies” defaults above depend on the selected security level:Secure Proxy Configuration
Override proxy behavior for the current security level:Double Iframe Configuration
Configure the outer iframe security barrier:Built-in Suspicious Patterns
These patterns are detected automatically whenblockSuspiciousSequences is enabled:
Custom Globals
Inject read-only data into the sandbox. Only JSON-serializable values are supported — functions cannot cross the iframe boundary. The constructor throws for a global that is or contains a function or symbol (also one hidden behindtoJSON()), a BigInt, a circular structure, or a value JSON would turn into {} (Map, Set, RegExp, DOM node, …), and for an undefined global. The error names the global and the path (Custom global "cfg" contains a function at "hooks.0.run"), so the problem shows up before any script runs. Dates are passed as ISO strings.
__safe_ prefix (e.g., config and __safe_config), matching the pattern used by AgentScript’s code transformation.
Tool Namespaces and callTool Options
callTool() call: counted toward maxToolCalls and checked by the outer iframe (rate limit, operation names, suspicious sequences). With { throwOnError: false }, a failing tool resolves to { success: false, error: { name, message, code?, toolName } } and a working one to { success: true, data }; refusals by the enclave still throw.
Related
- Overview - Getting started
- Security Architecture - Isolation model details
- @enclave-vm/core Configuration - Node.js configuration reference
- Security Levels - Security preset details