CodeRunnerCAUTION
A local sandbox for your AI agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/instavm/coderunner/stargazers) [](https://github.com/instavm/coderunner/blob/master/LICENSE)
CodeRunner helps you sandbox your AI agents and its actions inside a sandbox.
Key use case: You can run multiple Claude Code or AI agents in our sandbox without any fear of data loss and exfilteration.
For cloud managed VMs for agents, we have launched - InstaVM - Instant computers for AI agents
Quick Start
Prerequisites: Mac with macOS and Apple Silicon (M1/M2/M3/M4), Python 3.10+
git clone https://github.com/instavm/coderunner.git cd coderunner chmod +x install.sh ./install.sh
Stop and resume
Stop the sandbox when you are done:
container stop coderunner
Resume the same sandbox later, preserving uploads, kernels, and installed packages:
container start coderunner
To start over with a clean sandbox, delete the container and run the installer again:
container delete coderunner && ./install.sh
Disable outbound network access
By default, code running in the sandbox has unrestricted network access. To run it on a host-only network with no internet access:
CODERUNNER_NETWORK=none ./install.sh
In this mode, the MCP server is available at http://127.0.0.1:8222/mcp. The setting is fixed when the container is created; the installer refuses to resume a container with a different network mode.
Run Claude Code inside a Sandbox
./install.sh (if not already done)
container exec -it coderunner /bin/bash
root@coderunner:/app# npm install -g @anthropic-ai/claude-code
10cdc81f33e5OBSERVED · 2026-09-26Exposed tools (8)
5 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
execute_python_code | write | |
get_skill_file | read | |
get_skill_info | read | |
list_python_sessions | read | List active named Python sessions. |
list_skills | read | |
navigate_and_get_all_visible_text | read | |
start_python_session | write | Start a named Python session with an isolated persistent kernel. |
stop_python_session | write | Stop a named Python session and discard its kernel state. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (12 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
"http://127.0.0.1:*",
JUPYTER_HTTP_URL = "http://127.0.0.1:8888"
streamable-http
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"get_skill_file","arguments":{"skill_name":"..","filename":"../../../../etc/passwd"}}}')In this mode, the MCP server is available at `http://127.0.0.1:8222/mcp`. The setting is fixed when the container is created; the installer refuses to resume a container with a different network mode.
openai-agents
duckdb, jupyter-server, bash_kernel, fastapi, uvicorn, websockets, httpx, python-multipart
3. Start executing Python code with full access to the sandboxed environment
All rights granted under this License are granted for the term of copyright on the Program, and are irrevocable provided the stated conditions are met. This License explicitly affirms your unlimited p
images/runcode.png
Gates applied: no_behavioural_pass.
10cdc81f33e5full audit observations/trust-audit/mcp-server/instavm__coderunner.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | 10cdc81f33e5 | CAUTION | B | 89 | first audit |
Questions
What is the CodeRunner MCP server?
A local sandbox for your AI agents
What tools does CodeRunner expose?
8 in total: 5 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CodeRunner safe to connect to an agent?
With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does CodeRunner need?
No credential environment variables were found in its source, so it appears to need none.
How does CodeRunner run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (10cdc81f33e5), read on 2026-09-26. The repository is watched and re-audited when it changes.