API

Complete CLI surface and registry protocol. Every command supports --json; global flags are --home <path> and --json.

Tool lifecycle #

wasmbox install <name> [--registry URL] [--allow CAP]... [--allow-all]

Resolve name across configured registries, fetch the manifest, download the binary, verify SHA-256, prompt for capabilities, cache.

--registry URL
Pin source registry instead of searching all configured.
--allow CAP
Pre-grant a capability (stdin, stdout, filesystem:<path>, network:<host>, env:<NAME>). Repeat for multiple.
--allow-all
Grant every capability the manifest requests without prompting. Used by install.sh and CI scripts.
wasmbox list [--json]

List installed tools with version, install date, and registry source. --json emits an array of objects.

wasmbox search <query> [--json]

Search the cached index of each configured registry. Index cache TTL is 1 hour. --json emits matching tools.

wasmbox info <name> [--json]

Show manifest metadata, capabilities, and the [agent] block. JSON output includes agent.modes and agent.exit_codes for agent consumption.

wasmbox verify <name>

Recompute SHA-256 of the cached binary and compare in constant time against the manifest. Exit 0 on match, exit 3 on mismatch.

wasmbox update <name>

Fetch latest manifest, show old vs new hash and any new capabilities, prompt to apply. Previous version kept for rollback. Never automatic.

wasmbox remove <name>[@<version>]

Remove all versions, or a specific pinned version. Permissions for the removed version are also dropped from permissions.toml.

Execution #

wasmbox run <name> [--sandbox] [--allow CAP]... [--allow-all] [-- <tool args>]

Run an installed tool. Hash is re-verified before every execution. Arguments after -- are forwarded to the guest. Stdin/stdout are wired through when those capabilities are granted.

--sandbox
Force zero capabilities regardless of stored grants — useful for dry-running an untrusted tool.
--allow CAP
Add a capability for this run only. Not persisted to permissions.toml.
--allow-all
Skip prompts when stdin isn't a TTY. Exits 2 if grants are missing and prompts are unavailable.
wasmbox run --file <path.wasm> [--sandbox] [--allow CAP]... [-- <tool args>]

Run a local .wasm file directly without registry lookup. No manifest, no hash check — explicit caller responsibility.

Permissions #

wasmbox permissions <name> [show|revoke] [--json]

Show currently granted capabilities for a tool, or revoke all of them. show is the default.

wasmbox revoke <name> <capability>

Revoke a single capability (e.g. wasmbox revoke crypts network). Next run will re-prompt or fail with exit 2.

wasmbox audit [--json] [--export PATH] [--format json|md|csv] [--sign] [--init-key] [--verify FILE]

List all granted permissions across all tools. With --export generates a compliance report combining tool inventory, run log, and policy status. --sign adds Ed25519 signature; --init-key generates a keypair under ~/.wasmbox/; --verify validates a signed report.

Compliance (FSL) #

wasmbox log [--tool NAME] [--blocked] [--stats] [--export PATH] [--rotate] [--json]

Inspect the append-only run log at ~/.wasmbox/run.log. Filter by tool, show only blocked attempts, compute statistics, export for evidence, or rotate to start fresh.

wasmbox policy init [--name LABEL] [--approved-by EMAIL] [--enforcement enforce|warn|disabled]

Create ~/.wasmbox/policy.toml from currently installed tools — captures name, hash, capability set per tool.

wasmbox policy check | add <name> | diff | enforce

check verifies installed tools match policy. add approves a new tool. diff shows changes since last approval. enforce switches mode to blocking.

wasmbox policy agent --enable | wasmbox policy shell

Enable the agent shell wrapper that blocks raw system commands (jq, yq, base64, sha256sum, date, trufflehog, python -c, node -e) and redirects to sandboxed WasmBox equivalents. shell prints the wrapper script to stdout for installation.

Registry management #

wasmbox registry add <url> | list [--json] | remove <url>

Manage configured registries stored in ~/.wasmbox/registries.toml. URLs must be HTTPS; HTTP is rejected.

Utilities #

wasmbox hash <file> [--json]

Compute SHA-256 of a file. Output format sha256:<hex>. Use to fill the hash field of a tool manifest before publishing.

Registry protocol #

A registry is any static HTTPS host serving these endpoints. No auth, no cookies, no tracking. Any S3 bucket, GitHub Pages site, or plain nginx works.

EndpointReturnsNotes
GET /index.json{ registry, tools: [...] }List of {name, version, description}. Cached 1h client-side.
GET /tools/<name>.jsonManifest TOML as textStrict parser — unknown fields rejected. hash field is mandatory.
GET /tools/<name>.wasmRaw wasm32-wasip2 binarySHA-256 must match manifest. Verified in constant time.
GET /tools/<name>.mdAgent skill file (Markdown)Optional. Documents modes, examples, exit codes for agent consumption.

Demo registry: https://qstorage.quilibrium.com/wasmbox. Add with wasmbox registry add <url>.

Manifest example

[tool]
name = "fantasma"
version = "0.1.0"
description = "Message anonymiser. Strips PII locally."
author = "Aunova"
license = "MIT"
homepage = "https://aunova.net/fantasma"

[binary]
wasm = "fantasma.wasm"
hash = "sha256:a1b2c3d4..."

[capabilities]
stdin = true
stdout = true
network = ["api.example.com", "cdn.example.com:443"]
filesystem = [{ path = "~/Documents", read = true, write = false }]
env = ["LANG"]

[ui]
type = "cli"

[agent]
prompt = "Pipe text through stdin; redacted output to stdout."
skill = "fantasma.md"

[[agent.modes]]
flag = "--strict"
description = "Treat any ambiguous match as PII."
example = "echo 'call me at 555-1234' | wasmbox run fantasma -- --strict"

[agent.exit_codes]
0 = "Success"
1 = "Input error"

Exit codes #

CodeMeaning
0Success.
1General error: invalid args, malformed manifest, registry unreachable, IO failure.
2Permission denied: a required capability was missing and could not be prompted (non-TTY stdin without --allow-all or matching --allow).
3Hash verification failed: cached binary's SHA-256 does not match the manifest. Binary is not executed.