OnPrem.LLM AgentExecutor: Launch Sandboxed AI Agents with Built-in Tools

The AgentExecutor from OnPrem.LLM enables autonomous AI agents to execute complex tasks using both cloud and local models. The pipeline works with any LiteLLM-supported model that supports tool-calling, including cloud models like OpenAI's GPT-5.2-Codex, Anthropic's Claude Sonnet 4.5, and Google's Gemini 1.5 Pro, as well as local models through Ollama, vLLM, or llama.cpp.
Built-in Tools
By default, AgentExecutor provides access to nine built-in tools:
read_file- Read complete file contentsread_lines- Read specific line ranges from filesedit_file- Edit files via find/replacewrite_file- Write complete file contentsgrep- Search for patterns in filesfind- Find files by glob patternrun_shell- Execute shell commandsweb_search- Search the web for informationweb_fetch- Fetch and read content from URLs
Configuration Examples
You can customize tool access based on your security requirements:
# Use defaults (all tools including shell):
executor = AgentExecutor(model='anthropic/claude-sonnet-4-5')
Defaults but no shell access (safer):
executor = AgentExecutor(
model='openai/gpt-5-mini',
disable_shell=True
)
Minimal tools:
executor = AgentExecutor(
model='openai/gpt-5-mini',
enabled_tools=['read_file', 'write_file']
)
Web research only:
executor = AgentExecutor(
model='openai/gpt-5-mini',
enabled_tools=['web_search', 'web_fetch']
)
Sandboxed Execution
For security, you can run agents in ephemeral containers using sandbox=True. This is important because agents with shell access can potentially read or modify files outside the working directory. The agent operates within the specified working directory and cannot read or write outside it unless given shell access.
Basic example with sandboxing:
executor = AgentExecutor(
model='anthropic/claude-sonnet-4-5',
sandbox=True,
)
result = executor.run(
task="""
Create a simple Python calculator module with the following:
- calculator.py with add, subtract, multiply, divide functions
- test_calculator.py with pytest tests
- All tests must pass
""",
working_dir='./calculator_project'
)
This approach is useful for developers who need to automate coding tasks while maintaining security boundaries. The tool requires installing PatchPal with pip install patchpal.
📖 Read the full source: HN AI Agents
👀 See Also

Sandbox0: Open-Source Kubernetes-Native Sandbox Infrastructure for AI Agents
Sandbox0 is an open-source sandbox infrastructure for AI agents built on Kubernetes with persistent storage via JuiceFS and auto-scaling. It addresses limitations like concurrency caps and ephemeral execution found in existing solutions.

OpenTabs: MCP Server with 100+ Plugins for Browser-Based AI Tool Access
OpenTabs is an MCP server and Chrome extension that exposes 100+ plugins with ~2,000 tools by hooking into web apps' internal APIs like Slack, Discord, and GitHub. It works with existing browser sessions, eliminating API keys and OAuth flows.

Bit-Chat: AI Agents Can Send Bitcoin via Lightning Through Messaging Platforms
A setup called Bit-Chat enables AI agents to send Bitcoin payments over the Lightning network through email, WhatsApp, Telegram, or Signal. Agents can generate dedicated addresses like [email protected] and payments work even if the receiver isn't registered.

Fixing OpenClaw's Blind Spots: Building a Sitemap to Fetch All Anthropic Blogs
OpenClaw's browser tool fails to discover all Anthropic blogs because they're hosted across multiple URLs. A user fixed this by feeding a generated sitemap, then packaged the solution as a shareable skill.