Installs the Datadog AI Guard SDKs (Python ddtrace + Node dd-trace) and wires agentless credentials/env so AI apps and agents built inside the sandbox can screen LLM prompts, tool calls, and outputs for prompt injection, jailbreaks, tool misuse, and sensitive-data exfiltration via client.evaluate(...). Datadog API/APP keys are proxy-injected and never enter the container. Sets DD_* environment variables (last-wins if a later --kit overrides them). Layer it onto any agent base (claude, codex, gemini, …); no agent affinity.
| Name | Required | Default | Description |
|---|---|---|---|
apm | Optional | false | Send AI Guard evaluations as APM traces so they appear in the Datadog UI ("AI Guard / Submit your first trace"). "true" runs a Datadog Agent container in the sandbox (trace intake on 127.0.0.1:8126) that forwards through the credential-injecting proxy. Default "false" keeps the kit fully agentless — evaluate() still returns live verdicts for inline enforcement, they just won't show in the trace UI. |
env | Optional | sandbox | Value for DD_ENV (deployment environment tag). |
service | Optional | sbx-ai-guard | Value for DD_SERVICE (service name tag). |
site | Optional | datadoghq.com | Datadog site (DD_SITE): datadoghq.com | datadoghq.eu | us3.datadoghq.com | us5.datadoghq.com | ap1.datadoghq.com |
| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/credential@1 | Required | Datadog API key (sent as the DD-API-KEY header). | |
com.docker.sandbox/credential@1 | Required | Datadog application key (sent as the DD-APPLICATION-KEY header). | |
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit ajeetraina777/datadog-ai-guard-kit-v3:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbx