{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "microsoft-execution-containers",
    "name": "Microsoft Execution Containers",
    "vendor": "Microsoft",
    "vendorUrl": "https://github.com/microsoft/mxc",
    "kind": "sdk",
    "category": "code-sandboxes",
    "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
    "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
    "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
    "repo": "https://github.com/microsoft/mxc",
    "license": "MIT",
    "transports": [],
    "packages": [
      {
        "registry": "npm",
        "name": "@microsoft/mxc-sdk"
      },
      {
        "registry": "nuget",
        "name": "Microsoft.Mxc.Sdk"
      }
    ],
    "auth": "none",
    "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
    "pricing": "free",
    "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 1506,
      "npmWeekly": 471674,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
    "capabilities": [
      "sandbox.code",
      "sandbox.fs",
      "sandbox.persist"
    ],
    "tags": [
      "sdk",
      "open-source",
      "local",
      "free",
      "no-auth",
      "no-card",
      "typescript",
      "dotnet",
      "rust",
      "windows",
      "linux",
      "macos",
      "json-schema",
      "new-1.0"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 76.3,
      "grade": "BB",
      "agentReady": true,
      "rank": 34,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 74,
        "maintenance": 92,
        "payments": 60,
        "reliability": 81,
        "schema": 81,
        "security": 69,
        "transparency": 83
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 81,
          "points": 16.2,
          "reason": "Read with the local-software lines, because MXC is a library the owner runs. Official packages on npm, NuGet and crates.io. Node.js 24 or later is stated and Windows 11 builds are listed per release, but the README gives no minimum host version for Linux or macOS (18 of 20). The Build workflow runs lint, Windows, Linux and macOS builds and SDK unit and integration tests on every push to main. Of the last 14 completed runs on main, 10 passed and 4 failed, and the newest (7 October 2026) passed. A flaky test is tracked in issue #1365 (18 of 25). 38 open issues against 261 closed. Ten open issues carry the bug label, seven of them filed since 15 September, and three outside reports from 24 September to 2 October have no reply (19 of 25). The changelogs follow Keep a Changelog with breaking changes marked, and the v1.0.0 release notes have a breaking-changes section. The Node and .NET changelogs still list the V1 changes under Unreleased with no 1.0.0 heading (11 of 15). Version 1.0.0, which the release notes call the first stable release (15). It was published on 6 October 2026, two days before this check, and three backends are marked experimental."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 81,
          "points": 13.16,
          "reason": "Read as an SDK with a published request contract. A draft-07 JSON Schema for the stable 1.0.0 request sits in the repository, and the Node SDK ships TypeScript declarations (25). No llms.txt. The docs are Markdown files in the repository (5 of 10). The API reference states what each operation does and has a table for choosing between captured, piped and terminal execution, and the backend guides say which policies each backend enforces and which are cooperative (15 of 20). Containment is a closed union, network actions and clipboard levels are enums, the schema has 33 enums and 39 objects closed to extra properties, and 135 of 150 properties carry a description. `command` is one free string (13 of 15). Ten sample scenarios, each in Rust, .NET and Node. The 12 error codes are a closed type, but we found no page that explains each one (11 of 15). A versioned `/v1` entry point, a schema version table with retired contracts, a changelog for each SDK and GitHub release notes. The Node changelog has no 1.0.0 entry (12 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 74,
          "points": 12.03,
          "reason": "One request type with `command` as the only required field, and `run` returns stdout, stderr, the exit code, a timeout flag and warnings. We found no documented cap on captured output, and the npm package is a 37.7 MB tarball (18 of 25). `spawn` streams output and `timeoutMs` bounds a run, but there is no truncation or size control on captured output (10 of 20). `MxcError` carries one of 12 codes with optional operation, native code and remediation, and a deny-and-record mode lists blocked accesses on ProcessContainer (18 of 20). `validate*` calls dry-run every lifecycle step, and lifecycle state errors are typed (`already_started`, `stale_id`). Issue #1429, open since 6 October, reports a second deprovision returning success. Not an MCP server, so no tool annotations apply (13 of 20). Network, filesystem and UI policy default to deny, and official SDKs exist for Node.js, .NET and Rust (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 69,
          "points": 12.08,
          "reason": "No credentials to issue or leak, because the library runs in the caller's process, so the middle band (20 of 30). Least privilege is the product's job. Egress, ingress and host loopback default to deny, filesystem access is limited to listed paths, UI access is denied when omitted, and validation rejects a policy the chosen backend can't enforce. The limits are documented. `isolation_session` cannot restrict networking, proxy routing is cooperative on Seatbelt and WSLC, the Windows DACL fallback that edits host file permissions is allowed by default, and `--audit` turns the sandbox off (17 of 20). The workload's output is untrusted content. The SDK keeps warnings and denial metadata out of stdout and stderr, but we found no guidance for an agent reading that output (8 of 15). Local JSON audit records for process exits, tier fallbacks, teardown and rejected configs through `--log-file` on the executors, and the deny-and-record capture. We found no equivalent switch documented for the in-process SDKs (10 of 15). SECURITY.md sends reports to MSRC, CodeQL runs in CI and the repository has a fuzzing pipeline. No advisories are published, although at least 20 enforcement gaps were fixed through public issues between August and October 2026. The security.txt on microsoft.com expired on 23 September 2026, and the Node SDK's PATH-resolved `whoami` at import (issue #1265) has had no reply since 24 September (14 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Read with the self-hosted rule. No x402, MPP or L402 (0 of 40). MIT software with nothing to buy and no hosted option, so 20 for pricing, 20 for free use with no card and 20 because an agent can install it from npm with no account."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 92,
          "points": 8.05,
          "reason": "v1.0.0 on 6 October 2026 (30). Three npm releases in the last 90 days, 0.8.0 on 22 August, 0.9.0 on 28 September and 1.0.0 on 6 October (20). 261 issues closed against 38 open, with issue forms, triage labels and fixes that land within days (issue #1430 was opened on 6 October and closed on 7 October). Three outside bug reports filed between 24 September and 2 October have no comment (19 of 25). Official SDKs for Node.js, .NET and Rust, all at 1.0.0 (15). A package-lock check, CodeQL and Dependabot for GitHub Actions in CI. The npm package has no `repository` field and no provenance attestation (8 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "note": "editorial 86, provenance 79",
          "reason": "MIT for the repository and for the published npm package, whose `LICENSE.md` we compared with the repository's (30). Local software with no service behind it. The telemetry docs list what the optional Windows events contain (version, backend, bounded outcomes, policy fingerprints) and what they omit (commands, file paths, credentials, free-form error text), and the consent prompt links Microsoft's privacy statement. No retention period for those events is stated (24 of 30). The release notes name V1 as the compatibility boundary for 1.x under semver 2.0, breaking changes need a new versioned surface, and the schema docs mark retired contracts. No notice period with dates was found (12 of 20). Telemetry is disclosed in the README, off by default, opt-in for each run, subject to user consent and an administrative block, and absent on Linux and macOS (20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "One request type with `command` as the only required field, and `run` returns stdout, stderr, the exit code, a timeout flag and warnings. We found no documented cap on captured output, and the npm package is a 37.7 MB tarball (18 of 25). `spawn` streams output and `timeoutMs` bounds a run, but there is no truncation or size control on captured output (10 of 20). `MxcError` carries one of 12 codes with optional operation, native code and remediation, and a deny-and-record mode lists blocked accesses on ProcessContainer (18 of 20). `validate*` calls dry-run every lifecycle step, and lifecycle state errors are typed (`already_started`, `stale_id`). Issue #1429, open since 6 October, reports a second deprovision returning success. Not an MCP server, so no tool annotations apply (13 of 20). Network, filesystem and UI policy default to deny, and official SDKs exist for Node.js, .NET and Rust (15).",
          "maintenance": "v1.0.0 on 6 October 2026 (30). Three npm releases in the last 90 days, 0.8.0 on 22 August, 0.9.0 on 28 September and 1.0.0 on 6 October (20). 261 issues closed against 38 open, with issue forms, triage labels and fixes that land within days (issue #1430 was opened on 6 October and closed on 7 October). Three outside bug reports filed between 24 September and 2 October have no comment (19 of 25). Official SDKs for Node.js, .NET and Rust, all at 1.0.0 (15). A package-lock check, CodeQL and Dependabot for GitHub Actions in CI. The npm package has no `repository` field and no provenance attestation (8 of 10).",
          "payments": "Read with the self-hosted rule. No x402, MPP or L402 (0 of 40). MIT software with nothing to buy and no hosted option, so 20 for pricing, 20 for free use with no card and 20 because an agent can install it from npm with no account.",
          "reliability": "Read with the local-software lines, because MXC is a library the owner runs. Official packages on npm, NuGet and crates.io. Node.js 24 or later is stated and Windows 11 builds are listed per release, but the README gives no minimum host version for Linux or macOS (18 of 20). The Build workflow runs lint, Windows, Linux and macOS builds and SDK unit and integration tests on every push to main. Of the last 14 completed runs on main, 10 passed and 4 failed, and the newest (7 October 2026) passed. A flaky test is tracked in issue #1365 (18 of 25). 38 open issues against 261 closed. Ten open issues carry the bug label, seven of them filed since 15 September, and three outside reports from 24 September to 2 October have no reply (19 of 25). The changelogs follow Keep a Changelog with breaking changes marked, and the v1.0.0 release notes have a breaking-changes section. The Node and .NET changelogs still list the V1 changes under Unreleased with no 1.0.0 heading (11 of 15). Version 1.0.0, which the release notes call the first stable release (15). It was published on 6 October 2026, two days before this check, and three backends are marked experimental.",
          "schema": "Read as an SDK with a published request contract. A draft-07 JSON Schema for the stable 1.0.0 request sits in the repository, and the Node SDK ships TypeScript declarations (25). No llms.txt. The docs are Markdown files in the repository (5 of 10). The API reference states what each operation does and has a table for choosing between captured, piped and terminal execution, and the backend guides say which policies each backend enforces and which are cooperative (15 of 20). Containment is a closed union, network actions and clipboard levels are enums, the schema has 33 enums and 39 objects closed to extra properties, and 135 of 150 properties carry a description. `command` is one free string (13 of 15). Ten sample scenarios, each in Rust, .NET and Node. The 12 error codes are a closed type, but we found no page that explains each one (11 of 15). A versioned `/v1` entry point, a schema version table with retired contracts, a changelog for each SDK and GitHub release notes. The Node changelog has no 1.0.0 entry (12 of 15).",
          "security": "No credentials to issue or leak, because the library runs in the caller's process, so the middle band (20 of 30). Least privilege is the product's job. Egress, ingress and host loopback default to deny, filesystem access is limited to listed paths, UI access is denied when omitted, and validation rejects a policy the chosen backend can't enforce. The limits are documented. `isolation_session` cannot restrict networking, proxy routing is cooperative on Seatbelt and WSLC, the Windows DACL fallback that edits host file permissions is allowed by default, and `--audit` turns the sandbox off (17 of 20). The workload's output is untrusted content. The SDK keeps warnings and denial metadata out of stdout and stderr, but we found no guidance for an agent reading that output (8 of 15). Local JSON audit records for process exits, tier fallbacks, teardown and rejected configs through `--log-file` on the executors, and the deny-and-record capture. We found no equivalent switch documented for the in-process SDKs (10 of 15). SECURITY.md sends reports to MSRC, CodeQL runs in CI and the repository has a fuzzing pipeline. No advisories are published, although at least 20 enforcement gaps were fixed through public issues between August and October 2026. The security.txt on microsoft.com expired on 23 September 2026, and the Node SDK's PATH-resolved `whoami` at import (issue #1265) has had no reply since 24 September (14 of 20).",
          "transparency": "MIT for the repository and for the published npm package, whose `LICENSE.md` we compared with the repository's (30). Local software with no service behind it. The telemetry docs list what the optional Windows events contain (version, backend, bounded outcomes, policy fingerprints) and what they omit (commands, file paths, credentials, free-form error text), and the consent prompt links Microsoft's privacy statement. No retention period for those events is stated (24 of 30). The release notes name V1 as the compatibility boundary for 1.x under semver 2.0, breaking changes need a new versioned surface, and the schema docs mark retired contracts. No notice period with dates was found (12 of 20). Telemetry is disclosed in the README, off by default, opt-in for each run, subject to user consent and an administrative block, and absent on Linux and macOS (20)."
        },
        "sources": [
          {
            "what": "repository README (backends, packages, telemetry summary, audit mode)",
            "url": "https://github.com/microsoft/mxc/blob/main/README.md",
            "seen": "2026-10-08"
          },
          {
            "what": "v1.0.0 release notes",
            "url": "https://github.com/microsoft/mxc/releases/tag/v1.0.0",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry record (versions, dates, engines, maintainers)",
            "url": "https://registry.npmjs.org/@microsoft/mxc-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@microsoft/mxc-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "Rust crate record",
            "url": "https://crates.io/api/v1/crates/mxc-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "NuGet registration record",
            "url": "https://api.nuget.org/v3/registration5-gz-semver2/microsoft.mxc.sdk/index.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK README",
            "url": "https://github.com/microsoft/mxc/blob/main/sdk/node/README.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK changelog",
            "url": "https://github.com/microsoft/mxc/blob/main/sdk/node/CHANGELOG.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Node V1 operation signatures",
            "url": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/node/v1/api.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Node V1 types, including the error codes",
            "url": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/node/v1/types.md",
            "seen": "2026-10-08"
          },
          {
            "what": "configuration schema, network defaults and contract versions",
            "url": "https://github.com/microsoft/mxc/blob/main/docs/schema.md",
            "seen": "2026-10-08"
          },
          {
            "what": "stable 1.0.0 JSON Schema",
            "url": "https://github.com/microsoft/mxc/blob/main/schemas/stable/mxc-config.schema.1.0.0.json",
            "seen": "2026-10-08"
          },
          {
            "what": "telemetry policy and consent",
            "url": "https://github.com/microsoft/mxc/blob/main/docs/telemetry.md",
            "seen": "2026-10-08"
          },
          {
            "what": "telemetry architecture, event contents and local audit records",
            "url": "https://github.com/microsoft/mxc/blob/main/docs/development/architecture/telemetry.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Windows build requirements",
            "url": "https://github.com/microsoft/mxc/blob/main/docs/backends/process-container/os-version-support.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Seatbelt backend guide (cooperative proxy)",
            "url": "https://github.com/microsoft/mxc/blob/main/docs/backends/seatbelt/seatbelt-backend.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Build workflow runs on main",
            "url": "https://github.com/microsoft/mxc/actions/workflows/Build.yml?query=branch%3Amain",
            "seen": "2026-10-08"
          },
          {
            "what": "open issues",
            "url": "https://github.com/microsoft/mxc/issues",
            "seen": "2026-10-08"
          },
          {
            "what": "issue on the PATH-resolved whoami at import",
            "url": "https://github.com/microsoft/mxc/issues/1265",
            "seen": "2026-10-08"
          },
          {
            "what": "issue on LXC container-to-host egress, closed 16 September 2026",
            "url": "https://github.com/microsoft/mxc/issues/998",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisories",
            "url": "https://github.com/microsoft/mxc/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "Microsoft security reporting policy",
            "url": "https://github.com/microsoft/.github/blob/main/SECURITY.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.microsoft.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "announcement on the Windows Developer Blog, 2 June 2026",
            "url": "https://blogs.windows.com/windowsdeveloper/2026/06/02/windows-platform-security-for-ai-agents/",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/microsoft.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The scout was right on vendor, packages, licence and category. One correction. The repository now carries a stability label, because the v1.0.0 release notes of 7 October 2026 call it the first stable release. The June blog's early preview label predates that.",
          "The repository README names the product Microsoft eXecution Container (MXC), and the blog and the npm description say Microsoft Execution Containers. The listing uses the blog's form.",
          "Why npm shows 471,674 weekly downloads for a package that reached 1.0.0 on 6 October. The blog says GitHub Copilot CLI adopted MXC, which may account for it, but we did not confirm the dependency.",
          "Whether MXC falls under a Microsoft bug bounty programme. SECURITY.md points to MSRC in general terms.",
          "Whether the 20 or more enforcement gaps fixed through public issues between August and October 2026 affected any published npm version on a default backend. We took no deduction.",
          "unchecked: the GitHub REST API refused our reader with a rate limit, so the repository's creation date, the full release asset list and reply times on issues were not read. Star count and release dates came from the web pages.",
          "unchecked: how long Microsoft retains the optional Windows telemetry events.",
          "unchecked: nothing was installed or run. Start time, isolation and enforcement claims are the vendor's documentation, not our measurement."
        ]
      },
      "negative": 0,
      "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
      "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
      "strengths": [
        "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
        "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
        "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
        "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
        "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
      ],
      "weaknesses": [
        "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
        "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
        "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
        "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
        "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
      ],
      "agentNotes": [
        "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
        "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
        "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
        "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
        "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 76.3
        }
      ],
      "editorialScores": {
        "ergonomics": 74,
        "maintenance": 92,
        "payments": 60,
        "reliability": 81,
        "schema": 81,
        "security": 69,
        "transparency": 86
      },
      "provenanceScore": 79
    },
    "connect": {
      "install": "npm install @microsoft/mxc-sdk"
    },
    "letme": {
      "capability": "https://letme.dev/sandbox.code",
      "tool": "https://letme.dev/microsoft-execution-containers"
    },
    "sameCompany": [
      "azure-foundry-fine-tuning",
      "azure-ai-content-safety",
      "azure-speech-to-text",
      "azure-text-to-speech",
      "microsoft-agent-framework",
      "microsoft-entra-agent-id",
      "azure-key-vault",
      "azure-devops-mcp",
      "microsoft-learn-mcp",
      "playwright-mcp",
      "azure-mcp",
      "azure-translator",
      "microsoft-graph-calendar",
      "dynamics-365-sales",
      "microsoft-advertising-api",
      "microsoft-excel-graph",
      "outlook-mail-graph"
    ],
    "notable": [
      "v1.0.0 was published to npm and crates.io on 6 October 2026 and to NuGet and GitHub releases on 7 October. The release notes call it the first stable release and commit the 1.x line to semver 2.0 (https://github.com/microsoft/mxc/releases/tag/v1.0.0)",
      "Microsoft announced MXC on 2 June 2026 as an early preview. The same post says GitHub Copilot CLI adopted MXC process isolation and that NVIDIA's OpenShell on Windows is built on it (https://blogs.windows.com/windowsdeveloper/2026/06/02/windows-platform-security-for-ai-agents/)",
      "Nine backends are named in the README. `processcontainer` is the Windows default, `bubblewrap` the Linux default and `seatbelt` the only macOS backend. `windows_sandbox`, and `microvm` and `hyperlight` on Windows, are marked experimental (https://github.com/microsoft/mxc/blob/main/README.md)",
      "Network policy is deny by default. Egress, ingress and host loopback each resolve to `deny` when the request omits them (https://github.com/microsoft/mxc/blob/main/docs/schema.md)",
      "Telemetry is off unless the run opts in, the Windows user has consented and administrative policy permits it. It is a no-op on Linux and macOS, and local open-source builds send nothing to Microsoft (https://github.com/microsoft/mxc/blob/main/docs/telemetry.md)",
      "On Windows the Node SDK runs `whoami` through the shell when the module loads, resolved from PATH. The report has been open since 24 September 2026 and the call is still in the published 1.0.0 package (https://github.com/microsoft/mxc/issues/1265)",
      "npm recorded 471,674 downloads of @microsoft/mxc-sdk in the week of 28 September to 4 October 2026, against 20 total downloads of the Rust crate published on 6 October (https://api.npmjs.org/downloads/point/last-week/@microsoft/mxc-sdk; https://crates.io/crates/mxc-sdk)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "Interfaces",
        "value": "Node.js `@microsoft/mxc-sdk/v1`, .NET `Microsoft.Mxc.Sdk.V1` and Rust `mxc_sdk::v1`, loaded in the host application's process. Executor binaries such as `wxc-exec.exe` take a JSON request for testing or where the SDK can't be embedded. No MCP server and no HTTP API (https://github.com/microsoft/mxc/blob/main/README.md)"
      },
      {
        "label": "Backends",
        "value": "Windows 11 x64 and ARM64 with `processcontainer` (default), `isolation_session`, `wslc`, and experimental `windows_sandbox`, `microvm` and `hyperlight`. Linux x64 and ARM64 with `bubblewrap` (default), `lxc`, `microvm` and `hyperlight`. macOS ARM64 and x64 with `seatbelt`"
      },
      {
        "label": "V1 creation choices",
        "value": "The Node V1 `Containment` union accepts `process` (the default intent), `processcontainer`, `wslc`, `lxc`, `seatbelt`, `isolation_session` and `bubblewrap` (https://github.com/microsoft/mxc/blob/main/docs/api-reference/node/v1/types.md)"
      },
      {
        "label": "Operations",
        "value": "`run` for captured output, `spawn` for live pipes, `spawnWithPty` for a terminal, then `provisionContainer`, `startContainer`, `runInContainer`, `stopContainer` and `deprovisionContainer` for persistent containers, and `validate*` dry-runs (https://github.com/microsoft/mxc/blob/main/docs/api-reference/node/v1/api.md)"
      },
      {
        "label": "Policy",
        "value": "Filesystem lists (`readonlyPaths`, `readwritePaths`, `deniedPaths`), directional network rules by CIDR, protocol and port or a caller-managed proxy, and UI controls for clipboard and input injection. Network defaults to deny in every direction"
      },
      {
        "label": "Persistence",
        "value": "Provision, start, execute, stop and deprovision for `isolation_session` and `wslc` only in V1. No snapshot or pause and resume was found in the reviewed documentation"
      },
      {
        "label": "Request schema",
        "value": "Draft-07 JSON Schema for the stable 1.0.0 contract at schemas/stable/mxc-config.schema.1.0.0.json. 0.9.0-alpha is the minimum supported contract and 1.1.0-alpha is the development contract (https://github.com/microsoft/mxc/blob/main/docs/schema.md)"
      },
      {
        "label": "Errors",
        "value": "`MxcError` with 12 codes (`malformed_request`, `unsupported_containment`, `backend_unavailable`, `stale_id`, `policy_validation`, `backend_error` and others), plus optional `operation`, `nativeCode` and `remediation`"
      },
      {
        "label": "Runtimes",
        "value": "Node.js 24 or later, and on Windows 24.21.0 or 26.8.0 for native stdio. Rust is pinned to 1.93 for source builds. Windows 11 24H2 needs build 26100.9278 for process isolation and 26100.9550 for session isolation (https://github.com/microsoft/mxc/blob/main/docs/backends/process-container/os-version-support.md)"
      },
      {
        "label": "Packages",
        "value": "npm @microsoft/mxc-sdk 1.0.0 (6 October 2026, 37.7 MB tarball with native binaries for every platform), crates.io mxc-sdk 1.0.0 (6 October), NuGet Microsoft.Mxc.Sdk 1.0.0 (7 October)"
      },
      {
        "label": "Telemetry",
        "value": "Off by default. Official builds can send ETW diagnostic events on Windows only when the run opts in, the user has consented and policy under HKLM\\SOFTWARE\\Policies\\Mxc permits. The docs say events hold no commands, file paths or credentials"
      },
      {
        "label": "Diagnostics",
        "value": "`--debug` output, a deny-and-record capture of blocked accesses on ProcessContainer, and local JSON audit records through `--log-file` on the executors. `--audit` disables the sandbox and is for trusted tools only"
      },
      {
        "label": "Security reporting",
        "value": "SECURITY.md sends reports to MSRC, Microsoft's security response team. No advisories are published on the repository (https://github.com/microsoft/mxc/security/advisories)"
      }
    ],
    "provenance": {
      "legalEntity": "Microsoft Corporation",
      "domain": "microsoft.com",
      "domainRegistered": "1991-05-02",
      "endpointOnVendorDomain": null,
      "terms": "",
      "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
      "statusPage": "",
      "changelog": "https://github.com/microsoft/mxc/releases",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
        "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
        "RDAP for microsoft.com gives a registration date of 1991-05-02.",
        "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
        "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
        "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
      ],
      "score": 79,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Microsoft Corporation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "microsoft.com, registered 1991-05-02 (35 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "nothing hosted, so the MIT licence stands in",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "",
          "state": "none-found",
          "points": 0,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://go.microsoft.com/fwlink/?linkid=521839",
          "state": "unreadable",
          "reason": "robots.txt asks readers like ours not to fetch it",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
    "live": {
      "slug": "microsoft-execution-containers",
      "versions": [
        {
          "registry": "github",
          "name": "microsoft/mxc",
          "version": "v1.0.0",
          "released": "2026-10-07",
          "seenAt": "2026-10-08T16:20:44.186904887Z"
        },
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk",
          "version": "1.0.0",
          "seenAt": "2026-10-08T16:20:42.947200785Z"
        }
      ],
      "githubStars": 1580,
      "npmWeekly": 471674,
      "securityTxt": {
        "url": "https://microsoft.com/.well-known/security.txt",
        "state": "expired",
        "expires": "2026-09-23T16:00:00.000Z",
        "checkedAt": "2026-10-08T15:39:08.216544687Z"
      },
      "pages": [
        {
          "url": "https://go.microsoft.com/fwlink/?linkid=521839",
          "kind": "privacy",
          "status": 0,
          "checkedAt": "2026-10-08T18:20:40.027295892Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "blockedByRobots": true
        }
      ],
      "updatedAt": "2026-10-08T18:20:40.027295892Z"
    }
  }
}
