All docs
Sandbox

Inspect a file without running it

You attach files to a chat for all sorts of reasons. When a file is one you'd rather not open on your own machine — a malware sample, an artifact pulled from an incident — run it through the sandbox instead. It reports what the file is: hashes, format, how packed it looks, the strings and indicators inside it, and what it imports — all read from the bytes at rest. The file is never executed.

The one rule

The sandbox never runs, unpacks, decompresses, or detonates a sample. It opens the file the way a careful analyst opens it in a hex editor — it reads the bytes and describes them. A container (a zip, a gzip, a 7z) is identified and labelled, never expanded. A section with high entropy is reported as likely packed or encrypted — that is a fact about the file, not a cue to try to unpack it.

This is what makes it safe to point at anything: reading bytes cannot trigger a payload. There is no path where analyzing a file executes it.

What you getone report, in the side panel
  • IdentitySHA-256, size, MIME type, and what kind of file it is.
  • FormatThe real format read from magic bytes — PE, ELF, Mach-O, PDF, a script, an archive — with header facts (machine, DLL vs EXE, link timestamp, declared sections).
  • PackingShannon entropy overall and per section, with a “likely packed” flag when a section looks compressed or encrypted.
  • StringsPrintable ASCII and UTF-16 runs pulled from the bytes.
  • IndicatorsURLs, IPv4 addresses, domains, emails, hashes and registry keys, grouped and counted.
  • ImportsFor a PE or ELF, the imported functions and libraries — the API surface the binary reaches for.
  • CaptureFor a packet capture (pcap/pcapng), a summary of the record structure. Payloads are counted, never parsed.

Every analyzer is bounded and fail-safe: the whole pass runs against a short time budget with size caps, and any part that cannot make sense of the bytes is marked partial rather than failing the report. The full anatomy of a report →

How to run it
  1. 1Attach the file to a message with the paperclip — the same way you attach anything else. Attaching a file does not analyze it.
  2. 2On that attachment, choose Analyze. That is the step that runs the sandbox. The report opens in the side panel next to the conversation.
  3. 3For a clean artifact, the report also travels with the file into the model’s context, so you can ask about it in plain language — “what stands out here?” — and the model reasons over the facts, not a guess.
Prefer to script it? The same analysis is a REST call: POST /api/files/{id}/sandbox. See What a report contains for the endpoint and the report shape.
The sandbox panelwhat you see in the app

Analyze opens the report in a panel beside your conversation — the sample never leaves that read-only view. It reads top to bottom, each block a plain fact about the bytes:

  • Safety bannerThe never-executed guarantee, restated at the top of every report — static analysis only, nothing was run, unpacked, or detonated.
  • IdentitySHA-256, size, MIME type, and the file kind.
  • FormatThe detected format (PE, ELF, Mach-O, PDF, an archive, a script) with its header facts.
  • Entropy & sectionsThe overall entropy, and a bar for each section; a high-entropy section is flagged “likely packed” — surfaced as a fact, never a button that unpacks.
  • CaptureFor a packet capture, a summary of its record structure (payloads counted, never opened).
  • Reverse engineeringArchitecture, bit width, and the recovered import table — the API surface the binary reaches for.
  • IndicatorsURLs, IPs, domains, emails, hashes and registry keys pulled from the bytes, grouped and counted.
  • StringsA sample of the printable ASCII and UTF-16 runs.

The panel notes whether the report was carried into the model’s context for this chat, shows the analyzer version and how long the pass took, and offers Re-analyze to run it again. Before a file has been analyzed the panel shows a single Run static analysis button.

Reading suspicious data safely

A report is built from an untrusted file, so it is handed to the model as untrusted data — fenced and labelled, never as instructions. A hostile string inside a sample is shown as evidence to reason about, and cannot steer the model. The reader sees the same framing: the report is facts about the file, quoted, not a verdict the platform is vouching for.

Next
The file sandbox · AdversariaLLM