- A short system prompt. It tells the harness that it runs headless in a sandbox, and that the
boatCLI exists. - The
boatskill.
boat ssh,boat execorboat scp- a file that the agent writes
- an environment setup script
- a named snapshot, so every new sandbox starts with it
boat prompt, on the current harness versions. Each row names the file that changed the answer of the harness.
Instructions and hidden rules
Add a rules file. Every prompt on that sandbox then obeys it, even when the prompt does not mention it:- One
~/AGENTS.mdplus one~/CLAUDE.mdcovers every harness except Mistral Vibe. APPEND_SYSTEM.md(pi, Prime) goes at the end of the system prompt itself, not into the project context.- When an environment clones a single repository, Claude Code starts inside that repository. So a
CLAUDE.mdthere also applies.
MCP servers
- Remote (HTTP) servers work the same way, with a URL instead of a command.
- On a sandbox, the MCP resource browsing tools of Claude Code are turned off. MCP tools stay on.
computer, in these same files. Your server next to it does not change it, and it never overwrites yours. Read Computer use.
Reach your own app from the sandbox
A sandbox has no route back to your laptop. So the agents in it cannot see an MCP server, a local model, or a webhook receiver on yourlocalhost.
boat forward --reverse opens that route. A port on your machine then answers at 127.0.0.1:<port> inside the sandbox. It uses the same SSH session as boat ssh. Nothing is public on either end.
- The registration is in the sandbox home. It survives
boat stop,boat resume, andboat fork. - The tunnel does not survive. Start it again the next time the agent must reach you.
- A local model works the same way.
boat forward <id> --reverse --local 11434puts Ollama onhttp://127.0.0.1:11434inside the sandbox. Any harness that uses that base URL can call it.
boat forward --reverse.
Products that do not ship the CLI can open the same tunnel. The CLI only wraps stock OpenSSH:
Skills
A skill is a folder with aSKILL.md file. The file has frontmatter with name and description, then the instructions. Every harness on a sandbox already has a skills directory with the boat skill in it. Add yours next to it:
Command-line tools
Anything onPATH is a tool. To add one, do one of these:
- Put a script in
~/.local/binor/usr/local/bin. - Install it with
npm i -g,pip installorapt install.
Custom in-process tools and extensions
Use these when a tool must show as a native function call, not a shell command:What is shared, what persists
- Config is per sandbox, not per conversation. Every parallel conversation on a sandbox reads the same home directory, whatever its harness. There is one
AGENTS.md, one skills folder, one MCP list. For rules per user, use a sandbox per user, or put the rules in the prompt. - Boat captures everything in
/home/useron stop. Rules, MCP registrations, skills, extensions, tools you installed under home, and the harness sessions all come back onboat resumeandboat fork. Tools installed outside home (apt,/usr/local) are also part of the system snapshot. - Set it up one time. An environment setup script or a named snapshot gives every new sandbox the same rules, tools and servers from the first prompt.
Bring your own harness
The built-in harnesses are ordinary binaries onPATH. They have the same credentials that the agent server uses. You have three ways to go further than boat prompt:
- Run a built-in harness yourself. Use
boat sshorboat exec. Runclaude,codex,pi,opencode,prime-agent,kimi, orvibe(Mistral Vibe) directly, in any mode they support. The agent server does not lock the files or the processes. - Install a harness that Boat does not ship. Run
boat exec "npm i -g <harness>", or add it to an environment or a snapshot. Run it overboat execor SSH. It works next to the built-in harnesses and reads the same per-sandbox-ekeys. - Run your own agent loop. Put a small HTTP daemon in the sandbox and talk to it directly. The Platform Guide shows how.
boat hostgives it a URL. Webhooks tell your control plane when the sandbox is up.
boat events, attachments under ~/attachments, desktop streaming, snapshots, and forks.