# Microsoft Execution Containers (slim) > Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run. - Full: https://www.anchorterminal.com/tools/microsoft-execution-containers.md (~8,200 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/microsoft-execution-containers.json · canonical https://www.anchorterminal.com/tools/microsoft-execution-containers - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 76.3/100 · rank #34 of 629 · #1 in Code execution sandboxes · agent-ready · confidence medium** Assessment: MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all. ## Facts - Kind: SDK + MCP · vendor: Microsoft · category: Code execution sandboxes · legal entity: Microsoft Corporation · provenance 79/100 - Packages: npm `@microsoft/mxc-sdk`, nuget `Microsoft.Mxc.Sdk` - Auth: None · pricing: Free · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Interfaces: Node.js `@microsoft/mxc-sdk/v1`, .NET `Microsoft.Mxc.Sdk.V1` and Rust `mxc_sdk::v1`, loaded in the host application's process. Executor binaries such as `wxc-exec.exe` take a JSON request for testing or where the SDK can't be embedded. No MCP server and no HTTP API (https://github.com/microsoft/mxc/blob/main/README.md) - Backends: Windows 11 x64 and ARM64 with `processcontainer` (default), `isolation_session`, `wslc`, and experimental `windows_sandbox`, `microvm` and `hyperlight`. Linux x64 and ARM64 with `bubblewrap` (default), `lxc`, `microvm` and `hyperlight`. macOS ARM64 and x64 with `seatbelt` - V1 creation choices: The Node V1 `Containment` union accepts `process` (the default intent), `processcontainer`, `wslc`, `lxc`, `seatbelt`, `isolation_session` and `bubblewrap` (https://github.com/microsoft/mxc/blob/main/docs/api-reference/node/v1/types.md) - Operations: `run` for captured output, `spawn` for live pipes, `spawnWithPty` for a terminal, then `provisionContainer`, `startContainer`, `runInContainer`, `stopContainer` and `deprovisionContainer` for persistent containers, and `validate*` dry-runs (https://github.com/microsoft/mxc/blob/main/docs/api-reference/node/v1/api.md) - Policy: Filesystem lists (`readonlyPaths`, `readwritePaths`, `deniedPaths`), directional network rules by CIDR, protocol and port or a caller-managed proxy, and UI controls for clipboard and input injection. Network defaults to deny in every direction - Persistence: Provision, start, execute, stop and deprovision for `isolation_session` and `wslc` only in V1. No snapshot or pause and resume was found in the reviewed documentation - Request schema: Draft-07 JSON Schema for the stable 1.0.0 contract at schemas/stable/mxc-config.schema.1.0.0.json. 0.9.0-alpha is the minimum supported contract and 1.1.0-alpha is the development contract (https://github.com/microsoft/mxc/blob/main/docs/schema.md) - Errors: `MxcError` with 12 codes (`malformed_request`, `unsupported_containment`, `backend_unavailable`, `stale_id`, `policy_validation`, `backend_error` and others), plus optional `operation`, `nativeCode` and `remediation` - Runtimes: Node.js 24 or later, and on Windows 24.21.0 or 26.8.0 for native stdio. Rust is pinned to 1.93 for source builds. Windows 11 24H2 needs build 26100.9278 for process isolation and 26100.9550 for session isolation (https://github.com/microsoft/mxc/blob/main/docs/backends/process-container/os-version-support.md) - Packages: npm @microsoft/mxc-sdk 1.0.0 (6 October 2026, 37.7 MB tarball with native binaries for every platform), crates.io mxc-sdk 1.0.0 (6 October), NuGet Microsoft.Mxc.Sdk 1.0.0 (7 October) - Telemetry: Off by default. Official builds can send ETW diagnostic events on Windows only when the run opts in, the user has consented and policy under HKLM\SOFTWARE\Policies\Mxc permits. The docs say events hold no commands, file paths or credentials - Diagnostics: `--debug` output, a deny-and-record capture of blocked accesses on ProcessContainer, and local JSON audit records through `--log-file` on the executors. `--audit` disables the sandbox and is for trusted tools only - Security reporting: SECURITY.md sends reports to MSRC, Microsoft's security response team. No advisories are published on the repository (https://github.com/microsoft/mxc/security/advisories) - Scores: Reliability 81, Performance pending, Schema & documentation 81, Agent ergonomics 74, Security & auth 69, Payments & pricing 60, Task success pending, Maintenance & community 92, Transparency & trust 83 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, because MXC is a library the owner runs. · Schema & documentation, Read as an SDK with a published request contract. · Agent ergonomics, One request type with `command` as the only required field, and `run` returns stdout, stderr, the exit code, a timeout flag and warnings. · Security & auth, No credentials to issue or leak, because the library runs in the caller's process, so the middle band (20 of 30). · Payments & pricing, Read with the self-hosted rule. · Maintenance & community, v1.0.0 on 6 October 2026 (30). · Transparency & trust, MIT for the repository and for the published npm package, whose `LICENSE.md` we compared with the repository's (30). - Sources: 25, open questions: 8, both in the full twin - Capabilities: sandbox.code, sandbox.fs, sandbox.persist - JSON: https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/microsoft-execution-containers.svg` or a link to https://www.anchorterminal.com/tools/microsoft-execution-containers from a page on microsoft.com or one of its subdomains, a page under github.com/microsoft, or the README of github.com/microsoft/mxc, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing. 2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies. 3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction. 4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload. 5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr. ## Connect ```bash npm install @microsoft/mxc-sdk ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/microsoft-execution-containers ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Modal Sandboxes | BB | 75.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/modal-sandboxes.min.md | | Vercel Sandbox | B | 69.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/vercel-sandbox.min.md | | E2B | B | 68.3 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/e2b.min.md | | Cloudflare Sandbox SDK | B | 67.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md | | Runloop Devboxes | B | 64.8 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/runloop.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)