█

AI/TLDR

Microsoft Execution Containers (MXC)

Policy-driven containment for AI agents and untrusted code on Windows, Linux and macOS

Diagram: Microsoft Execution Containers in the middle, linking agents to files, mail, web, data and code tools
MXC sits between an agent and the resources it is allowed to reachWindows Developer Blog ↗
Code Sandboxes & IsolationOpen source
Updated
7 Oct 2026
Language
Rust
License
MIT
Coverage
1 story
$npm install @microsoft/mxc-sdk

What's new

7 Oct 2026

Microsoft made MXC generally available on Windows 11 at its Windows hybrid intelligence event, with GitHub Copilot, OpenAI Codex, OpenClaw, Replit, LM Studio and Unsloth AI already supporting it and Claude Code among the agents coming next.

Latest news

Overview

Microsoft Execution Containers (MXC) is a policy-driven execution layer for untrusted code and dynamically generated workloads — model output, plugins, tools, agent harnesses or whole agents. A developer declares what the workload needs, such as the files it may read or write and the network destinations it may reach, and MXC enforces that boundary with a suitable container. The policy sits outside the workload's control, so an agent or the code it generates cannot grant itself more access.

One JSON configuration schema and typed SDKs for Rust, .NET and Node hide the platform differences. MXC maps the requested controls onto a backend for each operating system: AppContainer-based process containers on Windows 11, Seatbelt on macOS and Bubblewrap on Linux. Windows 11 also offers session containers (a separate OS session with its own identity, desktop, clipboard and input), WSL containers for a Linux environment, and an experimental microVM backend for a hardware-backed boundary.

Policies can run in three modes. Enforcement blocks anything not granted; learning mode also blocks it but writes a JSON activity report that helps you author a policy; permissive mode allows and records ungranted operations while you draft one. Microsoft announced MXC as an early preview at Build 2026 and made it generally available on October 7, 2026, with agents such as GitHub Copilot, OpenAI Codex, OpenClaw, Replit, LM Studio and Unsloth AI already integrating it.

What it does

  • One policy for files (read-only, read-write and denied paths), network egress and UI access such as clipboard and display
  • Policy enforced outside the workload, so an agent cannot widen its own permissions
  • Process containers on all three OSes: AppContainer on Windows 11, Seatbelt on macOS, Bubblewrap on Linux
  • Windows-only session containers and WSL containers, plus experimental microVM and Hyperlight backends
  • Enforcement, learning and permissive modes, with JSON activity reports for writing a policy
  • Typed SDKs on crates.io (mxc-sdk), NuGet (Microsoft.Mxc.Sdk) and npm (@microsoft/mxc-sdk)
  • Telemetry off by default; it needs an opt-in, user consent and permitting admin policy

Getting started

You do not need to clone the repository: install an SDK for your language from its package manager and spawn a workload with a containment request. The examples below use the Node SDK from the README.

Install the Node SDK

The same SDK is published for Rust (crates.io: mxc-sdk) and .NET (NuGet: Microsoft.Mxc.Sdk).

bashbash
npm install @microsoft/mxc-sdk

Run a command with network egress denied

A ContainerRequest names the command, the network policy and a timeout; spawn() runs it inside the default backend for your OS.

typescripttypescript
import { spawn, type ContainerRequest } from '@microsoft/mxc-sdk/v1';

const request: ContainerRequest = {
  command: 'node -e "console.log(\'hello from container\')"',
  network: { egress: { default: 'deny' } },
  timeoutMs: 30_000,
};

const child = await spawn(request);

Debug a policy from the command line

On Windows the wxc-exec tool runs a JSON config directly. Never use its --audit flag on untrusted code: it turns off all sandbox security for the workload.

bashbash
wxc-exec.exe --debug config.json

Commands and code are distilled from the project's own documentation — always check the official repo for the latest.

When to use it

  • Let a coding agent run the commands it writes while keeping it away from the rest of the disk and the network
  • Contain third-party plugins or MCP tools inside a desktop app with a declared, reviewable policy
  • Give an IT team one place to cap what local agents may touch, enforced by the OS rather than by each agent
  • Draft a least-privilege policy by running a workload in learning mode and reading its activity report

How Microsoft Execution Containers (MXC) compares

Microsoft Execution Containers (MXC) alongside other open-source code sandboxes & isolation tools AI/TLDR tracks, ranked by GitHub stars.

ToolStarsWhat it does
Daytona★ 71.6kDaytona is an open-source runtime that spins up isolated sandboxes in under 90ms so agents can safely run and persist AI-generated code.
NVIDIA NemoClaw★ 22.7kNVIDIA's reference stack for running OpenClaw, Hermes and LangChain Deep Agents Code inside OpenShell sandboxes, adding managed inference, network policy, snapshots and CLI lifecycle control.
OpenSandbox★ 15.7kOpenSandbox gives AI agents a safe place to run code and commands, with one unified API across Docker and Kubernetes runtimes and SDKs in five languages.
OpenShell★ 15.5kNVIDIA's open-source runtime that runs autonomous AI agents in sandboxes, enforcing a declared policy on every file access, syscall and network connection and formally verifying policy changes.
E2B★ 14.2kE2B is open-source infrastructure that runs AI-generated code inside secure, isolated cloud sandboxes, controlled from JavaScript or Python SDKs.
AX (Agent Executor)★ 13.3kGoogle's declarative orchestrator for agent workloads: a Task runs untrusted agent code in a sandbox, while Workspace, Gateway and Model resources wire up its repos, network allowlist and LLM credentials.
Astrid★ 10.3kA portable Rust runtime that executes software as sandboxed WebAssembly capsules, where every file, network, process and tool call is gated by a signed, revocable, per-principal capability instead of ambient authority.
Microsoft Execution Containers (MXC)★ 1.7kPolicy-driven containment for AI agents and untrusted code on Windows, Linux and macOS