Handler runtime
serviceValidate/run JS handlers in micro-VM.
Pre-release code-acting agent runtime executing generated JavaScript handlers inside hardware-isolated Hyperlight micro-VMs with explicit host capabilities.
Pre-release code-acting agent runtime executing generated JavaScript handlers inside hardware-isolated Hyperlight micro-VMs with explicit host capabilities.
export HYPERAGENT_PROMPT="Create a Markdown report from the input data and save it to disk"
docker run -it --rm \
--device=/dev/kvm \
--group-add $(stat -c '%g' /dev/kvm) \
--user "$(id -u):$(id -g)" \
-e HOME=/home/hyperagent \
-e GITHUB_TOKEN="$(gh auth token)" \
-e HYPERAGENT_PROMPT \
-v "$HOME/.hyperagent:/home/hyperagent/.hyperagent" \
-v "$HOME/.hyperagent/tmp:/tmp" \
-v "$(pwd)":/workspace -w /workspace \
ghcr.io/hyperlight-dev/hyperagent:latest --auto-approve --profile file-builderEach card below corresponds to a component identified in the repository research. Open a component record for its path, purpose, capabilities, dependencies, risks, and relationships.
Validate/run JS handlers in micro-VM.
Path-jailed file/domain-scoped HTTP capabilities.
PPTX/XLSX/PDF/Markdown/HTML outputs.
Expose approved MCP tools as host modules.
pptx/pdf/xlsx/report/data/API/web/MCP guidance.
These capabilities are derived from the current first-party README and supporting documentation. Names follow upstream terminology so you can search the source documentation precisely.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns why hyperagent?. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns what can you do with hyperagent?. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns example prompts. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns build a powerpoint deck. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns create a pdf report. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns produce an excel workbook. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns work with microsoft 365 through mcp. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns analyse an api and save the output. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns how it works. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns built-in modules. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns skills and profiles. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Upstream treats this as a distinct part of hyperlight-dev/hyperagent. In plain language, use this area when your task concerns mcp servers. Begin with the documented default, test it on disposable input, and open the source section for its current options and limitations.
Start with one capability card instead of asking the repository to do everything at once. This makes permissions, inputs, and output easier to understand.
Use a sample URL, copied repository, test document, or sandbox account. Keep production credentials and irreplaceable files out of the first run.
Watch Terminal output or the host application's activity view. If the behavior differs from the README, stop with Control + C or cancel inside the host before retrying.
Check generated files, diffs, API responses, logs, or previews. Never assume “command finished” means the result is correct.
Record the working command and non-secret configuration in your project's README. Store secrets in the documented environment file or password manager.
These examples are selected from the repository's first-party documentation. Replace obvious placeholders, keep quotation marks intact, and run them only in the context indicated by the surrounding explanation.
export HYPERAGENT_PROMPT="Create a Markdown report from the input data and save it to disk"
docker run -it --rm \
--device=/dev/kvm \
--group-add $(stat -c '%g' /dev/kvm) \
--user "$(id -u):$(id -g)" \
-e HOME=/home/hyperagent \
-e GITHUB_TOKEN="$(gh auth token)" \
-e HYPERAGENT_PROMPT \
-v "$HOME/.hyperagent:/home/hyperagent/.hyperagent" \
-v "$HOME/.hyperagent/tmp:/tmp" \
-v "$(pwd)":/workspace -w /workspace \
ghcr.io/hyperlight-dev/hyperagent:latest --auto-approve --profile file-builder# Presentation specialist with file-building limits
hyperagent --skill pptx-expert --profile file-builder
# API/data workflow with web-research limits
hyperagent --skill api-explorer --profile web-research
# Multiple profiles stack by taking the max startup limits
hyperagent --profile "web-research heavy-compute"{
"mcpServers": {
"m365": {
"command": "node",
"args": ["/path/to/your/microsoft-365-mcp-server.js"],
"env": {
"M365_TOKEN": "${M365_TOKEN}"
},
"denyTools": ["delete_user", "send_mail"]
}
}
}None documented
A configuration file changes behavior without changing source code. Make one change at a time and keep a backup before editing JSON, TOML, YAML, or environment files.
None documented
Paths identify where the relevant implementation or generated files live. Paths beginning with ~ are inside your home folder.
GitHub/Copilot authentication
Prefer temporary, least-privileged credentials. Never commit .env, tokens, cookies, private keys, or session exports.
None documented
Check pricing, data retention, rate limits, and account permissions before enabling optional integrations.
git diff before committing.127.0.0.1 unless you intentionally secure and expose them.The manual reflects first-party files checked on August 18, 2026. It explains the indexed repository rather than promising that every optional third-party integration is available or safe.