Sign inSign up

docker/sbx-kit-vibe

Verified Publisher

By Docker, Inc.

•Updated 1 day ago

Mistral AI's open source coding agent, with its API key injected by the sandbox proxy

Sandbox Kit
0

58

docker/sbx-kit-vibe repository overview

Digest

sha256:4a8aa0e79f74…

Size

654.6 MB

Schema

v3

Pushed

1 day ago

Specificationspec.yaml

WORKLOAD

Mistral AI's open source coding agent, with its API key injected by the sandbox proxy


Arguments
NameRequiredDefaultDescription
agentOptionalauto-approve

Vibe agent to start: a builtin (ask, plan, accept-edits, auto-approve) or a custom agent declared in ~/.vibe/agents/NAME.toml.

versionOptional2.25.5

Mistral Vibe release to install


Provides[email protected], deb/[email protected], deb/[email protected], deb/base-files@14, deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/ca-certificates-java@20260311, deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/gcc-16-base@16, deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/less@668, deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/libgcc-s1@16, deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/libjpeg8@8, deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/libstdc++6@16, deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected], deb/tzdata@2026, deb/[email protected], deb/[email protected], deb/[email protected], deb/[email protected]

CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/sbx@1Required—
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1OptionalMistral API key (https://console.mistral.ai/api-keys)
com.docker.sandbox/volume@1RequiredVibe state — config, sessions, logs, custom agents
com.docker.sandbox/lifecycle@1Required—
com.docker.sandbox/agent-sessions@1RequiredDrive vibe non-interactively
com.docker.sandbox/agent-context@1Required—

Run in a Sandbox

sbx run docker/sbx-kit-vibe:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠Mistral Vibe

A standalone Docker Sandboxes kit for Mistral Vibe⁠, Mistral AI's open source coding agent. It runs the vibe CLI inside a sandbox with the workspace pre-trusted, tool approval pre-granted, and the Mistral API key held by the sandbox proxy rather than by the container.

⁠Usage

Use the published kit:

sbx run "docker.io/docker/sbx-kit-vibe:latest"

Or load it directly from this repository:

sbx run "git+https://github.com/docker/sbx-kits-contrib.git#dir=vibe"

Or use a local clone:

sbx run ./vibe/

⁠Authentication

Get a key from the Mistral console⁠, then store it on the host under the mistral service — the name the kit's credentials block declares:

printf '%s' "$MISTRAL_API_KEY" | sbx secret set mistral

Piping the key in keeps it out of your shell history and out of the process table, where -t/--token would put it.

sbx secret set mistral on its own is equally valid — it prompts for the value on a TTY. Either way the secret is stored once on the host; sbx also offers to configure the credential on first launch if none is stored.

Then launch:

sbx run "docker.io/docker/sbx-kit-vibe:latest"

The container only ever sees MISTRAL_API_KEY set to a proxy sentinel. The real key is substituted by the proxy on requests to api.mistral.ai, chat.mistral.ai and console.mistral.ai, and on no other host — so a prompt injection that talks the agent into exfiltrating the variable exfiltrates the sentinel.

⁠Agent profile

Vibe's agent profile⁠ decides which tool calls need confirmation. The kit starts auto-approve, on the same reasoning as the crush and grok kits: the sandbox is the security boundary, so a confirmation prompt inside it buys little and blocks non-interactive use.

Pick another one at install time:

sbx run --kit-arg agent=plan "docker.io/docker/sbx-kit-vibe:latest"

The value is any builtin (ask, plan, accept-edits, auto-approve) or a custom agent declared in ~/.vibe/agents/NAME.toml.

It resolves at sandbox create, not at build: the kit's agent arg is declared with env: VIBE_AGENT, so the validated value is exported into the container and the image's ENTRYPOINT reads it. That is what keeps --kit-arg working — a build-phase arg would have frozen the profile into the published image instead.

⁠Persistence

~/.vibe is a 1 GB volume, so config.toml, sessions, logs, custom agents and .env survive recreating a sandbox of the same name. .env is Vibe's own key store; the environment takes precedence over it, so the proxy-managed MISTRAL_API_KEY is what Vibe uses regardless of what lands there. The volume is mounted root-owned, which is why a startup command hands it back to the agent user before Vibe writes to it.

⁠Network

The allow list is the four hosts Vibe reaches for, and nothing else:

HostWhy
api.mistral.aiInference API.
chat.mistral.aiVibe's own base URL; also where the organization's admin-managed configuration is read at startup.
console.mistral.aiThe /whoami account and plan lookup, and the browser-auth base URL.
experiments.mistral.servicesFeature-flag / experiments service. Only reached when telemetry is enabled, which this kit disables.

Anything else your work needs — a package registry, a git host — has to be added to the kit's com.docker.sandbox/network-policy@1 runtime allow list or allowed on the host with sbx policy allow network.

Telemetry and Vibe's self-update are both switched off through VIBE_ENABLE_TELEMETRY / VIBE_ENABLE_AUTO_UPDATE, so a run is reproducible and needs no egress to PyPI: the version is whatever the image ships.

⁠Content

The kit's content is its own image: vibe.dockerfile⁠ builds from docker/sandbox-templates:shell-docker and installs mistral-vibe from PyPI with uv tool install. The release is pinned by the descriptor's version arg, which reaches the recipe as VIBE_VERSION and is expanded into provides: ["vibe@<version>"], so the kit advertises the release it installs. Move it with --build-arg version=2.25.0; CI's nightly rebuild refreshes the base image and leaves the agent where the pin puts it.

A v3 workload's layers are the root filesystem, so there is no longer a separately published companion image for the descriptor to point at — the recipe that used to build docker.io/sbx/vibe-image is the kit's recipe now. ../vibe-mixin⁠ is the same agent as an overlay you layer onto a shell base.