CodeRunner
A local sandbox for AI agents: they run code and actions in an isolated container exposed over MCP
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Executes arbitrary agent code
- By default sandbox code has network access
Install
Manual install
git clone https://github.com/instavm/coderunner.git
cd coderunner
chmod +x install.sh
./install.shNeeds a Mac on Apple Silicon. For no-network mode run CODERUNNER_NETWORK=none ./install.sh.
This is third-party code. Review the repository files before installing.
What it does
CodeRunner gives an agent a safe place to run code: actions happen inside an isolated container rather than directly on your machine. This lets you run several Claude Code or other agents without fear of data loss or exfiltration. The sandbox comes up locally through the Apple container on a Mac with Apple Silicon, and can be stopped and resumed while preserving uploads, kernels and installed packages. By default code has network access, but it can be turned off to work with no internet, and then the MCP server is available at a local address. Agents connect to the sandbox over MCP, and it ships example skills too.
Who it is for. For anyone running AI agents that execute code and wanting to isolate them from the main system.
Good fit when
- You need to run agent code isolated from your machine
- You run several agents and fear data loss
- You need a sandbox where the network can be turned off
Not a fit when
- You have no Mac on Apple Silicon
- You do not need code execution isolation
Example request
Run this data processing script in the sandbox so it does not touch my main systemLimitations
The sandbox runs on a Mac with macOS and Apple Silicon and relies on the Apple container, needing Python 3.10. Isolation lowers risk but does not guarantee full protection, especially with network access on. For cloud VMs the authors have a separate paid service.
How to disable. Stop and delete the container: container stop coderunner and container delete coderunner, and remove the server from your MCP config.
MCP
- Transport
- http
- Authentication
- not required
| Environment variables | |
|---|---|
| CODERUNNER_NETWORK | Set to none to run the sandbox with no network access |
Security check
- Executes arbitrary agent code
- By default sandbox code has network access
README in short
The README describes CodeRunner as a local sandbox for AI agents where code and actions run in an isolated container. The main use is running several agents without fear of data loss or exfiltration. The sandbox works through the Apple container on a Mac with Apple Silicon, can be stopped and resumed with state kept, and the network can be turned off. Agents connect over MCP, and example skills are included. Apache 2.0 licensed.
FAQ
Does the sandbox keep state?
Yes, container stop and container start resume the same sandbox with uploads, kernels and installed packages.
Can I turn off the internet?
Yes, CODERUNNER_NETWORK=none runs the sandbox with no network, and then the MCP server is at a local address.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything