Skip to main content
This page documents all configuration options for @enclave-vm/browser.

Quick Example

Core Options

Console Limits

Security Level Comparison

All “varies” defaults above depend on the selected security level:

Secure Proxy Configuration

Override proxy behavior for the current security level:

Double Iframe Configuration

Configure the outer iframe security barrier:

Built-in Suspicious Patterns

These patterns are detected automatically when blockSuspiciousSequences is enabled:

Custom Globals

Inject read-only data into the sandbox. Only JSON-serializable values are supported — functions cannot cross the iframe boundary. The constructor throws for a global that is or contains a function or symbol (also one hidden behind toJSON()), a BigInt, a circular structure, or a value JSON would turn into {} (Map, Set, RegExp, DOM node, …), and for an undefined global. The error names the global and the path (Custom global "cfg" contains a function at "hooks.0.run"), so the problem shows up before any script runs. Dates are passed as ISO strings.
Custom globals are only supported with the agentscript preset (the default). Using globals with other presets will throw an error.
Each custom global is also available with a __safe_ prefix (e.g., config and __safe_config), matching the pattern used by AgentScript’s code transformation.

Tool Namespaces and callTool Options

A namespace call is a callTool() call: counted toward maxToolCalls and checked by the outer iframe (rate limit, operation names, suspicious sequences). With { throwOnError: false }, a failing tool resolves to { success: false, error: { name, message, code?, toolName } } and a working one to { success: true, data }; refusals by the enclave still throw.