Sandbox

Your app at a commit, with a browser your agent drives.

Your agent asks for a sandbox. Taskr boots your app at the commit and seeds it, and the agent signs in and clicks through the bug in a real browser while Taskr records. No keys or tokens go inside.

The pictures in this section show Tom's Codex agent, the browser of a Taskr sandbox, the sandbox's status and issue TSK-148 in the Taskr web app. The agent opens a sandbox; Taskr boots the Acme Billing app at commit 4f2c1e9 and seeds it. The agent signs in as a seeded test user, opens invoice INV-2041 and replays its webhook, and the card is charged $48.00 twice. Taskr's recording lands on TSK-148. The same steps against the pull request's preview deployment charge the card once.

Sandbox

Watch your agent use the app.

Tom's Codex agent gets its own browser on a fresh copy of the app. It signs in, clicks through the bug, and Taskr records every step.

01 Open

One MCP call opens a sandbox.

sandbox_open and sandbox_close are MCP tools, so Codex, Cursor or Claude Code can call them. The agent pushes its branch and names the issue.

01 Open

Taskr boots the app at the commit and seeds it.

A microVM starts each process in order and waits until it is ready, then runs pnpm db:seed --profile bug-repro. No keys or tokens go inside.

02 Sign in

It signs in as a seeded test user.

The seed created seed-user@acme.test for this sandbox. It is never a real user's session, and the password is masked in the recording.

03 Re-enact

It clicks through the bug, step by step.

Invoices, INV-2041, Replay webhook: the card is charged $48.00 twice. Each action lands on the trace as it happens.

04 Recorded

Taskr records it, not the agent.

The trace, video, console and network log come from Taskr's recorder, which the agent cannot stop. When the sandbox closes, they land on TSK-148 as evidence.

05 Preview

Then the same steps on the preview.

In preview mode Taskr waits for the pull request's preview deployment and the browser tests that URL. Same steps on #212, and the card is charged once.

05 Preview

Before and after, on the issue.

Both recordings sit on TSK-148: the bug at 4f2c1e9 and the fix on the preview. Whoever reviews #212 can watch them before reading the diff.

How it works

What runs, what signs in, what gets kept.

Boot and seed

.taskr/agent.yml on your default branch says how to run the app. Taskr fetches the commit outside the sandbox, streams it into a microVM, starts each process in order and waits until each answers on its ready URL. Then it runs your seed.

app:
  mode: sandbox
  services:
    processes:
      - name: web
        run: pnpm --filter web start
        ready: http://localhost:3000
  seed:
    - pnpm db:seed --profile bug-repro
  viewport: 1280x800

Sign-in without real credentials

The browser signs in as a test user your seed creates, by filling the form or from a storage state a seed step writes. Never a real user's cookies.

No credentials or tokens go into the VM. Network access is denied by default, apart from package registries during setup and, in preview mode, the preview host.

What Taskr records

Your agent drives headless Chromium through a Playwright MCP that Taskr proxies. Taskr, not the model, records: the trace (actions, DOM snapshots, screencast, network and console), a video, and a HAR of the requests with their bodies left out.

Inputs and secrets are masked in the recordings. One sandbox can be open per agent session, and the recordings go to the issue as evidence.

Preview mode

Already deploy a preview for each pull request? Set mode: preview and Taskr skips the boot. It waits for the deployment through GitHub deployment events, from Vercel, Netlify or your own, and the browser tests that URL.

Record the bug before the fix and the same steps on the preview after it.

Put your agents on real tickets.

For the whole engineering team, and every agent that speaks MCP. We build Taskr for teams like ours.