deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

Microsoft open-sources MXC, a cross-platform sandbox for untrusted AI-generated code

Microsoft has released MXC, an open-source sandboxed execution system that runs untrusted code such as model output, plugins and tools behind one policy model on Windows, Linux and macOS.

Microsoft open-sources MXC, a cross-platform sandbox for untrusted AI-generated code

Microsoft has released MXC, short for Microsoft eXecution Container, an open-source system for executing untrusted code — model output, plugins and external tools — inside sandboxes on Windows, Linux and macOS. The repository sits in Microsoft's GitHub organisation, and its README reached the Hacker News front page on 9 October 2026. MXC is not a standalone product: it is an SDK dependency that builds into your application, which then declares the container type, the containment rules and the workload command. MXC validates that request, picks an appropriate backend, and launches the workload inside the resulting container.

One API, many containment backends

The core idea is a single programming interface stretched across very different isolation technologies, ranging from OS-native process sandboxes to full virtual machines. According to the project's README, defaults and options vary by platform:

  • Windows 11 on x64 and ARM64 defaults to ProcessContainer, with WSLC, IsolationSession, Windows Sandbox, MicroVM (Nanvix) and Hyperlight also available; Windows Sandbox, MicroVM and Hyperlight are flagged as experimental.
  • Linux on x64 and ARM64 defaults to Bubblewrap, with LXC, MicroVM and Hyperlight as alternatives.
  • macOS on ARM64 and x64 supports only Seatbelt, Apple's sandbox mechanism.

Policy-driven containment

Containment rules are expressed through versioned, JSON-based container-creation requests covering three domains. Filesystem policy marks paths as readable, writable or denied; network policy handles proxying, outbound controls and host filtering that depends on the chosen backend; and UI policy governs access to the clipboard, display and GUI. Containers are also state-aware, with a lifecycle of provisioning, starting, executing, stopping and deprovisioning, so they support persistent environments rather than only one-shot runs.

SDKs and standalone executors

Three SDKs are published through standard package managers: Rust on crates.io, .NET on NuGet and Node on npm. The Node and .NET packages bundle the native runtime assets, while the Rust crate compiles the engine and the selected backends directly into the consuming application. Where embedding an SDK is impractical, or for testing, platform-specific executor binaries such as wxc-exec.exe accept JSON requests defined by a stable schema. The README's Node sample launches a short script inside a container with outbound network access denied by default and a thirty-second timeout, showing how containment policy travels alongside the execution request.

Debugging when the sandbox bites

The documentation is candid that applications will encounter access-denied errors until their containment rules are tuned. Executors offer a debug flag that surfaces MXC diagnostics alongside the workload's own output, plus an audit mode that records every access a trusted tool attempts and generates the artifacts needed to author a ProcessContainer policy granting exactly those files and capabilities. Audit mode switches off all sandbox security for the workload being analysed, and the README warns explicitly that it must never be used to run untrusted code. A separate logging mode records blocked accesses without weakening isolation.

Telemetry and building from source

Official Microsoft builds can send optional diagnostic telemetry, but only when the individual run opts in, the Windows user has explicitly consented, administrative policy permits collection, and the application enables the option in the workload request. An administrator can block telemetry but cannot grant consent on a user's behalf. Telemetry is a no-op on non-Windows platforms, and locally built open-source binaries are not configured to send anything to Microsoft. Building from source requires Rust pinned to version 1.93 and Node.js 24 or later, plus the toolchain prerequisites of the chosen backend, with separate build scripts for Windows, Linux and macOS. Licensing terms are covered by the repository's LICENSE file.

Why it matters

Agent frameworks increasingly need to execute model-written code, and doing so on a user's machine without strong isolation is a real security risk. Isolation primitives already exist on every major OS, but their interfaces and capabilities differ enough that projects have traditionally either written per-platform integrations or fallen back on heavyweight virtual machines. MXC abstracts that spread behind one versioned, policy-oriented SDK available in Rust, .NET and Node, which makes it directly usable by the tooling layer of AI applications: code interpreters, plugin runners and agents that execute generated commands. The layered backend choice also lets developers trade compatibility against strength of isolation, from a lightweight process sandbox up to a microVM. Caveats remain — several backends are experimental, macOS has a single backend, and the telemetry behaviour deserves a careful read — but as shared infrastructure for safely running untrusted code, this is a release that builders of AI tooling can put to work immediately.

  • #microsoft
  • #sandbox
  • #ai-agents
  • #developer-tools
  • #open-source

Related posts