Atlas / MCP servers / instavm / CodeRunner

CodeRunnerCAUTION

mcp/instavm/coderunner

A local sandbox for your AI agents

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
8 5r · 3w · 0d
Transport
streamable-http
License
Apache-2.0
Stars
893
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/instavm/coderunner/stargazers) [](https://github.com/instavm/coderunner/blob/master/LICENSE)

CodeRunner helps you sandbox your AI agents and its actions inside a sandbox.

Key use case: You can run multiple Claude Code or AI agents in our sandbox without any fear of data loss and exfilteration.

For cloud managed VMs for agents, we have launched - InstaVM - Instant computers for AI agents

Quick Start

Prerequisites: Mac with macOS and Apple Silicon (M1/M2/M3/M4), Python 3.10+

git clone https://github.com/instavm/coderunner.git
cd coderunner
chmod +x install.sh
./install.sh

Stop and resume

Stop the sandbox when you are done:

container stop coderunner

Resume the same sandbox later, preserving uploads, kernels, and installed packages:

container start coderunner

To start over with a clean sandbox, delete the container and run the installer again:

container delete coderunner && ./install.sh

Disable outbound network access

By default, code running in the sandbox has unrestricted network access. To run it on a host-only network with no internet access:

CODERUNNER_NETWORK=none ./install.sh

In this mode, the MCP server is available at http://127.0.0.1:8222/mcp. The setting is fixed when the container is created; the installer refuses to resume a container with a different network mode.

Run Claude Code inside a Sandbox

./install.sh (if not already done)

container exec -it coderunner /bin/bash

root@coderunner:/app# npm install -g @anthropic-ai/claude-code

Read from source at commit 10cdc81f33e5OBSERVED · 2026-09-26
02

Exposed tools (8)

5 read · 3 write · 0 destructive.

ToolRiskDescription
execute_python_codewrite
get_skill_fileread
get_skill_inforead
list_python_sessionsreadList active named Python sessions.
list_skillsread
navigate_and_get_all_visible_textread
start_python_sessionwriteStart a named Python session with an isolated persistent kernel.
stop_python_sessionwriteStop a named Python session and discard its kernel state.
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (12 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server.py:61
"http://127.0.0.1:*",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server.py:78
JUPYTER_HTTP_URL = "http://127.0.0.1:8888"
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test-e2e.sh:75
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"get_skill_file","arguments":{"skill_name":"..","filename":"../../../../etc/passwd"}}}')
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:55
In this mode, the MCP server is available at `http://127.0.0.1:8222/mcp`. The setting is fixed when the container is created; the installer refuses to resume a container with a different network mode.
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/requirements.txt
openai-agents
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
duckdb, jupyter-server, bash_kernel, fastapi, uvicorn, websockets, httpx, python-multipart
Why it matters. 45 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:198
3. Start executing Python code with full access to the sandboxed environment
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
THIRD_PARTY_NOTICES.md:101
All rights granted under this License are granted for the term of copyright on the Program, and are irrevocable provided the stated conditions are met. This License explicitly affirms your unlimited p
INFOInventory / provenance · inv.oversize · CWE-1104
images/runcode.png
images/runcode.png
Why it matters. 8392982 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha 10cdc81f33e5full audit observations/trust-audit/mcp-server/instavm__coderunner.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2610cdc81f33e5CAUTIONB89first audit
05

Questions

What is the CodeRunner MCP server?

A local sandbox for your AI agents

What tools does CodeRunner expose?

8 in total: 5 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CodeRunner safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does CodeRunner need?

No credential environment variables were found in its source, so it appears to need none.

How does CodeRunner run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (10cdc81f33e5), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement