Inspect a file without running it
You attach files to a chat for all sorts of reasons. When a file is one you'd rather not open on your own machine — a malware sample, an artifact pulled from an incident — run it through the sandbox instead. It reports what the file is: hashes, format, how packed it looks, the strings and indicators inside it, and what it imports — all read from the bytes at rest. The file is never executed.
The sandbox never runs, unpacks, decompresses, or detonates a sample. It opens the file the way a careful analyst opens it in a hex editor — it reads the bytes and describes them. A container (a zip, a gzip, a 7z) is identified and labelled, never expanded. A section with high entropy is reported as likely packed or encrypted — that is a fact about the file, not a cue to try to unpack it.
This is what makes it safe to point at anything: reading bytes cannot trigger a payload. There is no path where analyzing a file executes it.
- IdentitySHA-256, size, MIME type, and what kind of file it is.
- FormatThe real format read from magic bytes — PE, ELF, Mach-O, PDF, a script, an archive — with header facts (machine, DLL vs EXE, link timestamp, declared sections).
- PackingShannon entropy overall and per section, with a “likely packed” flag when a section looks compressed or encrypted.
- StringsPrintable ASCII and UTF-16 runs pulled from the bytes.
- IndicatorsURLs, IPv4 addresses, domains, emails, hashes and registry keys, grouped and counted.
- ImportsFor a PE or ELF, the imported functions and libraries — the API surface the binary reaches for.
- CaptureFor a packet capture (pcap/pcapng), a summary of the record structure. Payloads are counted, never parsed.
Every analyzer is bounded and fail-safe: the whole pass runs against a short time budget with size caps, and any part that cannot make sense of the bytes is marked partial rather than failing the report. The full anatomy of a report →
- 1Attach the file to a message with the paperclip — the same way you attach anything else. Attaching a file does not analyze it.
- 2On that attachment, choose Analyze. That is the step that runs the sandbox. The report opens in the side panel next to the conversation.
- 3For a clean artifact, the report also travels with the file into the model’s context, so you can ask about it in plain language — “what stands out here?” — and the model reasons over the facts, not a guess.
POST /api/files/{id}/sandbox. See What a report contains for the endpoint and the report shape.Analyze opens the report in a panel beside your conversation — the sample never leaves that read-only view. It reads top to bottom, each block a plain fact about the bytes:
- Safety bannerThe never-executed guarantee, restated at the top of every report — static analysis only, nothing was run, unpacked, or detonated.
- IdentitySHA-256, size, MIME type, and the file kind.
- FormatThe detected format (PE, ELF, Mach-O, PDF, an archive, a script) with its header facts.
- Entropy & sectionsThe overall entropy, and a bar for each section; a high-entropy section is flagged “likely packed” — surfaced as a fact, never a button that unpacks.
- CaptureFor a packet capture, a summary of its record structure (payloads counted, never opened).
- Reverse engineeringArchitecture, bit width, and the recovered import table — the API surface the binary reaches for.
- IndicatorsURLs, IPs, domains, emails, hashes and registry keys pulled from the bytes, grouped and counted.
- StringsA sample of the printable ASCII and UTF-16 runs.
The panel notes whether the report was carried into the model’s context for this chat, shows the analyzer version and how long the pass took, and offers Re-analyze to run it again. Before a file has been analyzed the panel shows a single Run static analysis button.
A report is built from an untrusted file, so it is handed to the model as untrusted data — fenced and labelled, never as instructions. A hostile string inside a sample is shown as evidence to reason about, and cannot steer the model. The reader sees the same framing: the report is facts about the file, quoted, not a verdict the platform is vouching for.