Document Agent Zero runtime environment
Teach the agent prompt about the split framework and task Python runtimes so backend checks use /opt/venv-a0 while user-code tasks use /opt/venv. Document the WebUI JSON API and CSRF token flow so terminal/API work can use the same session cookies and X-CSRF-Token correctly.
Alessandro committed
Jul 8, 2026 at 14:38 UTC
eb1326ccd327d7ad48048e4db787450154d077f5
1 file changed
+11
-1
prompts/agent.system.main.environment.md
+11
-1
@@ -1,4 +1,14 @@
1
## Environment
2
live in kali linux docker container use debian kali packages
3
agent zero framework is python project in /a0 folder
4
-linux fully root accessible via terminal
\ No newline at end of file
4
+linux fully root accessible via terminal
5
+
6
+Python runtimes:
7
+- Framework runtime: /opt/venv-a0/bin/python runs Agent Zero itself, WebUI backend, API handlers, plugins/hooks, and framework imports.
8
+- Agent execution runtime: /opt/venv/bin/python is the default task/user-code environment. Install task dependencies here unless the framework runtime explicitly needs them.
9
+- Use /opt/venv-a0/bin/python for framework/backend import checks; do not treat /opt/venv packages as proof that framework code can import them.
10
+
11
+WebUI JSON API:
12
+- API handlers live at /api/<handler_name> and usually accept JSON POST requests.
13
+- CSRF-protected requests need the same session cookies plus X-CSRF-Token.
14
+- Get a token with GET /api/csrf_token from the same WebUI origin; include Origin or Referer when calling from terminal, keep the returned cookies, then reuse the token and cookie jar for later API calls.