RunnoBLOCK
Sandboxed runtime for programming languages and WASI binaries. Works in the browser, on your server, or via MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
👨💻 Use Runno 👉 Runno.dev
📖 Documentation 👉 Runno.dev
Runno is a collection of JavaScript Packages for running code in various languages inside a sandbox. It's made of the following packages:
- `@runno/runtime` - web components and headless tools for running code examples in the browser.
- `@runno/sandbox` - a secure sandbox for running code examples in Node and other JS Runtimes.
- `@runno/wasi` - an isomorphic package for running WebAssembly WASI binaries inside a sandbox.
- `@runno/mcp` - an MCP Server for running code using the
@runno/sandboxpackage.
There's also a deprecated Python package called `runno` that works like the sandbox package.
This project is powered by WASI the Web Assembly System Interface. It provides a standard way for programs to interact with an operating system. By emulating this interface, we can provide a fake file system and operating system, all running within JavaScript.
Using @runno/runtime
The @runno/runtime package provides Web Components for running code in the browser.
This is very handy for programming education it means:
- No need for newbies to install complex programming tools to run code
- Programming examples can be made runnable in the browser with no server
- Simple programs can be tested for correctness inside a sandbox on the user's machine
Quickstart
Start by adding @runno/runtime to your package:
npm install @runno/runtime
Import @runno/runtime in whatever place you'll be using the runno elements. The simplest is in your entrypoint file (e.g. main.ts or index.ts).
import "@runno/runt
054aba965527OBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp -- npx -y @runno/[email protected]
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
exec(req: ProcExecRequest): Result;
ruby-3.2.0.tar.gz
cat.wasi.wasm
cat.wasi.wasm
python-package.tar.gz
write.wasi.wasm
.firebaserc
.prettierignore
.env.development
.env.production
.env.development
packages/website/public/langs
import { Syntax } from "../../types";import { WASIFS } from "../../../types.js";import { WASIDrive } from "../../../wasi/wasi-drive.js";import type { WASIDrivePreopen } from "../../../wasi/wasi-drive.js";import { Result as Preview1Result } from "../../../wasi/snapshot-preview1.js";run: sudo apt-get update && sudo apt-get install -y wabt
sudo apt-get update && sudo apt-get install -y wabt \
lit, @tailwindcss/typography, autoprefixer, postcss, tailwindcss, typescript, vite
husky, lerna, lint-staged, prettier, typescript
@modelcontextprotocol/sdk, @runno/sandbox, zod-to-json-schema, @microsoft/api-extractor, tsup, typescript, vitest
@codemirror/basic-setup, @codemirror/gutter, @codemirror/highlight, @codemirror/lang-cpp, @codemirror/lang-javascript, @codemirror/lang-python, @codemirror/lang-sql, @codemirror/language
@runno/wasi, tar, @microsoft/api-extractor, tsup, typescript, vitest
[Wasmtime](https://wasmtime.dev/) and you can run the same command:
Gates applied: no_behavioural_pass.
054aba965527full audit observations/trust-audit/mcp-server/taybenlor__runno.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | 054aba965527 | BLOCK | D | 69 | first audit |
Questions
What is the Runno MCP server?
Sandboxed runtime for programming languages and WASI binaries. Works in the browser, on your server, or via MCP.
Is Runno safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Runno need?
No credential environment variables were found in its source, so it appears to need none.
How does Runno run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @runno/website at 0.10.3.
How current is this page?
The grade is for one exact copy of the source (054aba965527), read on 2026-09-27. The repository is watched and re-audited when it changes.