Gemini CLI sandbox: Multi-Profile, Remote Access, Docker, VS Code Companion, Git Worktree.
10K+
The zero-config, ultra-secure home for your Gemini AI agent. Run the Gemini CLI in a Dockerized sandbox that keeps your host system clean while staying fully integrated with your tools (VS Code, Docker, VPN, git worktree).
The Gemini Hub provides a centralized dashboard to discover, manage, and launch your sessions from any device (Desktop, Mobile, or Tablet) via Tailscale VPN.
Monitor all your active sessions at a glance. Identify projects, connection types (CLI/Bash), and status in real-time.

Start new sessions effortlessly by browsing your host's workspace roots. No need to remember complex CLI flags.

Toggle "Launch in Ephemeral Worktree" to experiment in a fully isolated branch without touching your primary codebase.

The gemini-toolbox script handles the complex Docker logic for you.
# Clone and enter the repo
git clone https://github.com/Jsebayhi/gemini-cli-toolbox.git
cd gemini-cli-toolbox
# Add to your PATH (Optional but recommended)
ln -s $(pwd)/bin/gemini-toolbox ~/.local/bin/gemini-toolbox
source completions/gemini-toolbox.bash
source completions/gemini-hub.bash
# Open interactive AI chat in the current folder
gemini-toolbox
The Toolbox isn't just a wrapper; it's a bridge between your host and a secure execution environment.
127.0.0.1 on your host, making them invisible to your local network (LAN).docker commands (build, run, compose) by talking to your host's daemon. It shares your local image cache for instant speed.--remote to access it from your phone, tablet, or another PC via a secure mesh network.http://gemini-hub:8888) to discover and manage multiple active sessions from any device connected to the VPN.--worktree to launch the agent in a dedicated, isolated worktree of your repository. Your main working directory remains untouched.:ro) to protect source code, while keeping the .git directory Read-Write (:rw) to allow the agent to commit and branch safely.π Read the full Architecture & Features Deep Diveβ for technical details on DooD, IDE mirroring, and VPN logic.
Want to go deeper? Follow these guides to master the Toolbox:
| Goal | Command |
|---|---|
| Simple Chat | gemini-toolbox |
| Stop Session | gemini-toolbox stop [id|project] |
| One-shot Task | gemini-toolbox -- -p "Fix the linting errors in src/" |
| Isolated Exploration | gemini-toolbox --worktree |
| Named Worktree | gemini-toolbox --worktree --name feat/auth |
| Pure Localhost | gemini-toolbox --no-vpn |
| Beta Features | gemini-toolbox --preview |
| Remote Coding | gemini-toolbox --remote |
| Disposable Shell | gemini-toolbox --bash |
Isolate your environments using configuration profiles.
# Use a specific profile (e.g., Work vs Personal)
gemini-toolbox --profile ~/.gemini-profiles/work
Launch a parallel session without stashing or committing your current work.
# Create an anonymous, isolated worktree for a quick experiment
gemini-toolbox --worktree -- -p "Try migrating to ESM"
# Or create a persistent, named branch for a feature
gemini-toolbox --worktree --name feat/api -- -p "Implement the new REST endpoints"
The agent works in an isolated environment. If the experiment fails, simply exitβthe Hub will clean it up later.
The Hub wizard automatically remembers your last 3 paths (stored in your browser's localStorage), making it effortless to jump back into a project from mobile.
extra-args)Inside a profile directory (when using --profile), create a file named extra-args to store flags you use every time. It supports blank lines and comments using #:
# ~/.gemini-profiles/work/extra-args
--volume "/mnt/data/docs:/docs" # Mount my documentation
--no-ide # Disable VS Code integration for this profile
--preview # Always use the latest beta features
Since sessions are fully sandboxed by default, language caches (Maven, Gradle, etc.) are ephemeral. To reuse your host's caches for faster builds, add them to your profile's extra-args:
# ~/.gemini-profiles/work/extra-args
--volume "/home/user/.m2:/home/gemini/.m2"
--volume "/home/user/.gradle:/home/gemini/.gradle"
--volume "/home/user/.npm:/home/gemini/.npm"
Keep your command history across container restarts:
gemini-toolbox -v ~/.gemini_bash_history:/home/gemini/.bash_history --bash
By default, worktrees are stored in ~/.cache/gemini-toolbox/worktrees. Override this with:
export GEMINI_WORKTREE_ROOT="/mnt/fast-ssd/worktrees"
gemini-toolbox --worktree
We love contributors! If you add or modify CLI flags, please remember to update the scripts in completions/. See CONTRIBUTING.mdβ for more details.
If you're contributing to the Toolbox, you can run the full suite of automated tests and linters:
# Run all tests (Bash & Hub), linters, and security scans
make local-ci
# Build specific image groups
make build-toolbox # Hub, CLI, CLI-Preview
make build-clis # CLI Stable and Preview only
# Run security vulnerability scan (Trivy)
make scan
# Run specific automated test suites
make test-bash # Bash core scripts (Bats)
make test-hub # Gemini Hub unit/integration (Pytest)
make test-hub-ui # Gemini Hub UI (Playwright)
We use Bats-coreβ for testing our core bash scripts. New tests should be added to tests/bash/.
MIT
Content type
Image
Digest
sha256:00fed8b27β¦
Size
259 Bytes
Last updated
5 months ago
docker pull jsebayhi/gemini-cli-toolbox:sha256-f395850b65da9ce06879427a5b69ec33200d2d34dd992509b9eee8eafd7c331b.sig