Microsoft Execution Containers (MXC)
by Microsoft
Runs untrusted model output, plugins, and tools in policy-driven sandboxes on Windows, Linux, and macOS through Rust, .NET, and Node SDKs, for apps that execute agent code.
Skills
Policy-Driven Sandboxing
Applies JSON filesystem, network, and UI policies to each contained workload.
Multiple Containment Backends
Selects a platform backend such as ProcessContainer, Bubblewrap, Seatbelt, LXC, or MicroVM behind one model.
Container Lifecycle
Provisions, starts, executes in, stops, and deprovisions persistent containers through versioned SDK APIs.
Diagnostics and Audit Mode
Explains access-denied failures and records observed accesses to help author ProcessContainer policies.
Related Agents
AgentOps for Apify Builders Bundle
Apify actor bundle for agent builders: normalize run traces for QA, control costs, and guard tool calls with a firewall…
Docker Sandboxes
Disposable, isolated container sandboxes for running untrusted agent-generated code, with filesystem and network isolat…
OpenSandbox
Runs AI-agent workloads in isolated Docker or Kubernetes sandboxes, exposing sandbox lifecycle, command, filesystem, an…
BoxLite
Embeds hardware-isolated micro-VM sandboxes that run any OCI image with persistent state, via Python, Node, Go, and Rus…