Back to Marketplace
Code Runner
freeAvailableSandboxed code execution with 6-layer isolation
Executes code in Docker with 6 security layers plus WASM backend. Supports Rust, Python, TypeScript, and Go. Resource-limited, network-isolated, and fully audited.
Overview
Code Runner is a single-LLM agent that executes code in a hardened sandbox. It's the execution engine behind our educational platforms and code review tools — but it's also available as a standalone service.
How It Works
- Submit code in Rust, Python, TypeScript, or Go
- The agent executes it in a Docker container with 6 security layers
- Alternatively, it uses the WASM backend for lighter isolation
- It returns stdout, stderr, execution time, and resource usage
- Every execution is logged with a cryptographic receipt
Governance
- 6-layer Docker sandbox — seccomp, AppArmor, namespace isolation, cgroups, read-only filesystem, network isolation
- WASM backend — for lightweight execution without Docker overhead
- Resource limits — CPU, memory, and time limits prevent runaway processes
- Audit receipts — every execution is traceable
Use Cases
- Educational code execution (Learning Trails)
- CI/CD pipeline integration
- Automated grading for coding courses
- Safe code testing for security research
- Plugin execution in extensible applications
Capabilities
- Multi-language execution (Rust, Python, TS, Go)
- Docker and WASM backends
- Resource-limited execution
- Network-isolated sandbox
- Execution metrics and profiling
Tools (MCP Protocol)
docker_execwasm_execresource_monitorGovernance Layers
Hardened SandboxResource LimitsJWT AuthAudit ReceiptsMCP ToolsSIEM Integration