Don't let your agents roam free in the wild: Mini Me gets its `sbx` kit
Build a Docker sbx kit for Mini Me to run the agent in an isolated sandbox, locally or from a remote repository, and extend it with additional kits.

Running an AI agent locally, directly on your machine, is not a good idea, and for plenty of good reasons. One of the first that comes to mind is "the agent can perform destructive actions on your machine", but an even more serious one, in my opinion, is this one: "the agent sees all your configurations, ssh keys, environment variables, secrets, ...".
That's why you need tools able to isolate the agent and protect your machine and your data, whatever "guardrails" instructions you may have given to your agent (they are usually easy to get around).
My tool of choice to secure the way my agents run is Docker sbx (disclaimer: I work at Docker). Docker sbx already supports the best-known agents on the market, like Claude Code, Codex, Copilot, .... And if your agent is not on the list, you can use kits to build an sbx sandbox specifically for your agent. That's what we're going to do today for Mini Me. You'll see, it's quick.
Building your kit locally
Create a mini-me folder in a project folder, with these two files:
mini-me.dockerfilemini-me.yaml
mini-me.dockerfile
# syntax=docker/dockerfile:1
FROM docker/sandbox-templates:shell
USER root
ARG TARGETARCH
ARG MM_VERSION
RUN <<EOF
set -eu
curl -fsSL "https://rickub.com/bots-garden/mini-me/releases/download/${MM_VERSION}/mm-${MM_VERSION#v}-linux-${TARGETARCH}" -o /usr/local/bin/mm
chmod 0755 /usr/local/bin/mm
EOF
# Back to the sandbox user, then declare the launch command.
USER agent
ENTRYPOINT ["mm"]
CMD ["-tui"]
mini-me.yaml
# syntax=docker/sandbox-kit:3
schemaVersion: "3"
kind: workload
displayName: Mini Me
description: Mini Me (mm), a minimalist coding agent for local LLMs
sourceUrl: https://rickub.com/bots-garden/mini-me
provides: ["mini-me@0.3.0"]
dockerfile: ./mini-me.dockerfile
args:
mm_version:
# A release tag of https://rickub.com/bots-garden/mini-me/releases
default: "v0.3.0"
pattern: '^v[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$'
buildArg: MM_VERSION
capabilities:
# The workload is prepared for sbx to launch it (agent user, bash, ...).
- type: com.docker.sandbox/sbx@1
# Egress is deny-by-default. mm talks to a model server running on the host.
# Check the port/host for your setup, then `sbx policy log` if it is blocked.
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- host.docker.internal:12434 # Docker Model Runner
- host.docker.internal:11434 # Ollama
- host.docker.internal:17434 # Llmman
Configuring the agent
In the project folder, add an agent.yaml file with the following content (adapt it to your needs):
agent.yaml
provider: llmman
model: hf.co/unsloth/gemma-4-E2B-it-GGUF:Q4_K_M
baseUrl: http://host.docker.internal:17434/v1
yolo: true
bashTool: true
editTools: true
displayCommands: true
showThinking: true
acp:
name: bob
title: Bob (coding agent)
# The system prompt: what the agent is, and what it is allowed to do.
system: |
Your name is Bob.
You are a coding agent working in a terminal.
sampling:
temperature: 0.0
parallel_tool_calls: false
top_p: 0.9
max_tokens: 4096
Don't forget to download the model with the following command:
llmman pull hf.co/unsloth/gemma-4-E2B-it-GGUF:Q4_K_M
Using the "Mini Me" kit in the project folder
Your project folder should look like this:
.
├── agent.yaml
└── mini-me
├── mini-me.dockerfile
└── mini-me.yaml
And to start Mini Me in a sandbox, run the following command (where mm-demo is the name of the sandbox):
sbx run --name mm-demo ./mini-me
And here is "Mini Me" running in an sbx sandbox:

If you want to use another configuration file for the "Mini Me" agent, use the following command:
sbx run --name mm-demo ./mini-me -- -tui -config agent.lucy.yaml
Using the "Mini Me" kit published on a remote repository
It's also possible to publish kits on Git repositories, or on registries. For now, I've published a "Mini Me" kit over here: https://rickub.com/bots-garden/mini-me-kit. Using it is simple (where v0.0.1 is the version of the kit):
RELEASE=v0.0.1
REPOSITORY=git+https://git.rickub.com/bots-garden/mini-me-kit.git
sbx run --name mm-demo-remote "${REPOSITORY}#ref=${RELEASE}&dir=mini-me"
If you need to add tools to the "Mini Me" kit, you can absolutely create "additional kits" that plug into the "Mini Me" kit, for example like this, where I add 2 extra kits:
sbx run --name mm-demo-remote "${REPOSITORY}#ref=${RELEASE}&dir=mini-me" \
--kit ./kits/go-toolchain --kit ./kits/cli-tools \
-- -tui -config agent.lucy.yaml
You can find the examples over here: https://rickub.com/bots-garden/mini-me/tree/main/sbx/kits.
There you go, you can now use the "Mini Me" agent with peace of mind.
Written by
Keep reading
Mini Me release v0.3.0
What is new in Mini Me v0.3.0, the Devoxx Belgium release: approval mode, agents calling agents, request traces, JSON answers, AGENTS.md and an sbx kit.

Hello Mini Me: an agent born while preparing a talk for Devoxx
Meet Mini Me, a coding agent born from a Devoxx talk on the agent loop, built for small local models with guardrails against loops and hallucinations.

No comments yet. Be the first to comment!