Atlas / MCP servers / taybenlor / Runno

RunnoBLOCK

mcp/taybenlor/runno

Sandboxed runtime for programming languages and WASI binaries. Works in the browser, on your server, or via MCP.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
773
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

👨💻 Use Runno 👉 Runno.dev

📖 Documentation 👉 Runno.dev

Runno is a collection of JavaScript Packages for running code in various languages inside a sandbox. It's made of the following packages:

  • `@runno/runtime` - web components and headless tools for running code examples in the browser.
  • `@runno/sandbox` - a secure sandbox for running code examples in Node and other JS Runtimes.
  • `@runno/wasi` - an isomorphic package for running WebAssembly WASI binaries inside a sandbox.
  • `@runno/mcp` - an MCP Server for running code using the @runno/sandbox package.

There's also a deprecated Python package called `runno` that works like the sandbox package.

This project is powered by WASI the Web Assembly System Interface. It provides a standard way for programs to interact with an operating system. By emulating this interface, we can provide a fake file system and operating system, all running within JavaScript.

Using @runno/runtime

The @runno/runtime package provides Web Components for running code in the browser.

This is very handy for programming education it means:

  • No need for newbies to install complex programming tools to run code
  • Programming examples can be made runnable in the browser with no server
  • Simple programs can be tested for correctness inside a sandbox on the user's machine

Quickstart

Start by adding @runno/runtime to your package:

npm install @runno/runtime

Import @runno/runtime in whatever place you'll be using the runno elements. The simplest is in your entrypoint file (e.g. main.ts or index.ts).

import "@runno/runt
Read from source at commit 054aba965527OBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add mcp -- npx -y @runno/[email protected]
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/wasi/lib/wasix/providers.ts:185
exec(req: ProcExecRequest): Result;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
langs/ruby-3.2.0.tar.gz
ruby-3.2.0.tar.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/runtime/public/cat.wasi.wasm
cat.wasi.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/public/cat.wasi.wasm
cat.wasi.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/public/python-package.tar.gz
python-package.tar.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/public/write.wasi.wasm
write.wasi.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.firebaserc
.firebaserc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/runtime/.env.development
.env.development
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/runtime/.env.production
.env.production
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/website/.env.development
.env.development
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
packages/website/public/langs
packages/website/public/langs
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/runtime/lib/elements/shared/codemirror.ts:10
import { Syntax } from "../../types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/wasi/lib/wasix/providers/ergonomic/filesystem-provider.ts:11
import { WASIFS } from "../../../types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/wasi/lib/wasix/providers/ergonomic/filesystem-provider.ts:12
import { WASIDrive } from "../../../wasi/wasi-drive.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/wasi/lib/wasix/providers/ergonomic/filesystem-provider.ts:13
import type { WASIDrivePreopen } from "../../../wasi/wasi-drive.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/wasi/lib/wasix/providers/ergonomic/filesystem-provider.ts:18
import { Result as Preview1Result } from "../../../wasi/snapshot-preview1.js";
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/test-on-pull-request.yml:21
run: sudo apt-get update && sudo apt-get install -y wabt
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
packages/wasi/tests/install-wasix-tools.sh:26
sudo apt-get update && sudo apt-get install -y wabt \
Why it matters. asks for elevated privileges
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/package.json
lit, @tailwindcss/typography, autoprefixer, postcss, tailwindcss, typescript, vite
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
husky, lerna, lint-staged, prettier, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp/package.json
@modelcontextprotocol/sdk, @runno/sandbox, zod-to-json-schema, @microsoft/api-extractor, tsup, typescript, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/runtime/package.json
@codemirror/basic-setup, @codemirror/gutter, @codemirror/highlight, @codemirror/lang-cpp, @codemirror/lang-javascript, @codemirror/lang-python, @codemirror/lang-sql, @codemirror/language
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/sandbox/package.json
@runno/wasi, tar, @microsoft/api-extractor, tsup, typescript, vitest
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
packages/website/src/pages/articles/ffmpeg.md:155
[Wasmtime](https://wasmtime.dev/) and you can run the same command:
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha 054aba965527full audit observations/trust-audit/mcp-server/taybenlor__runno.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-27054aba965527BLOCKD69first audit
05

Questions

What is the Runno MCP server?

Sandboxed runtime for programming languages and WASI binaries. Works in the browser, on your server, or via MCP.

Is Runno safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Runno need?

No credential environment variables were found in its source, so it appears to need none.

How does Runno run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @runno/website at 0.10.3.

How current is this page?

The grade is for one exact copy of the source (054aba965527), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement