Regarding files, they are volume mapped (local <--> sandbox) as with docker.
It's not agentic - agents can use it to execute code. Those agents can be powered by any LLM including local.