Skip to main content

weft-microsandbox

Microsandbox runner plugin for Weft.

This extension runs disposable command and one-shot provider_cli agent tasks inside Microsandbox microVM sandboxes. It is intended for probably-hostile tools, MCP servers, and skills that need a harder process and filesystem boundary than the host runner.

The runner name is microsandbox.

Install with:

uv add 'weft[microsandbox]'

The current Microsandbox SDK supports Linux x86_64/aarch64 and macOS Apple Silicon. The SDK is Apache-2.0 licensed. A working local Microsandbox runtime is required for real execution; weft spec validate --preflight --load-runner checks the local runtime gate explicitly.

Tool Mode

{
  "spec": {
    "type": "command",
    "process_target": "python",
    "args": ["-c", "print('hello')"],
    "runner": {
      "name": "microsandbox",
      "options": {
        "image": "python:3.12-alpine",
        "mode": "tool",
        "network": "none",
        "workspace_mode": "none"
      }
    }
  }
}

Agent Mode

{
  "spec": {
    "type": "agent",
    "persistent": false,
    "agent": {
      "runtime": "provider_cli",
      "conversation_scope": "per_message",
      "runtime_config": {
        "provider": "codex"
      }
    },
    "runner": {
      "name": "microsandbox",
      "options": {
        "image": "ghcr.io/acme/codex-provider:latest",
        "mode": "agent",
        "executable": "codex",
        "network": "allow",
        "workspace_mode": "none"
      }
    }
  }
}

runner.options.executable is the executable inside the guest image. It is not resolved on the host.

Runner Options

  • image: required OCI image.
  • mode: optional; derived from spec.type as tool for command tasks and agent for agent tasks.
  • executable: required for agent mode; guest-local provider CLI command.
  • network: none by default, or allow.
  • workspace_mode: none by default, or copy, mount-read-only, or mount-read-write.
  • mounts: explicit host mounts. Entries default to read-only.
  • cwd: guest working directory. Required for workspace modes.
  • sandbox_name_prefix: optional runtime name prefix.

Security Defaults

  • network defaults to none.
  • workspace_mode defaults to none.
  • host environment variables are not forwarded unless they are explicit in spec.env.
  • persistent and interactive tasks are rejected.

Current Limitations

Memory, CPU, and file-descriptor limits are passed to the Microsandbox SDK, but the runner does not yet map SDK OOM or metrics evidence to RunnerOutcome(status="limit"). A guest killed by the runtime for memory pressure may currently surface as a generic execution error.

This runner is a process, VM, and filesystem boundary. It is not a semantic defense against prompt injection or malicious output.

Metadata

Release files for weft-microsandbox 0.5.13

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for weft-microsandbox 0.5.13
File Size Uploaded
weft_microsandbox-0.5.13.tar.gz 12.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for weft-microsandbox 0.5.13
File Interpreter ABI Platform
weft_microsandbox-0.5.13-py3-none-any.whl Python 3 none any Details

Total release size: 28.0 kB

Release files / weft_microsandbox-0.5.13.tar.gz

Download URL weft_microsandbox-0.5.13.tar.gz
Size 12.2 kB
Tags Source
SHA-256 checksum
How to use checksums
ca353d8d741d7f23dcc7cd7fd9fc14cf34d45d7ff56c4b41b3009f948dfeef51
BLAKE2b-256 checksum
How to use checksums
0a6f4dc38d2b17d4395df6ae3177fceb541709356cf128e68527e119b21974bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / weft_microsandbox-0.5.13-py3-none-any.whl

Download URL weft_microsandbox-0.5.13-py3-none-any.whl
Size 15.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e9abf4127d9930fc8b540a635a7c585c1a9c9a5d48816b5944c56492a21f27b4
BLAKE2b-256 checksum
How to use checksums
780f6ab388e1acfa628067de0768e583834a6b286c9dae59fe560cf2e014b832
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

0.5.13 This release

2 release files

0.5.12

2 release files

0.5.11

2 release files

0.5.10

2 release files

0.5.9

2 release files

0.5.8

2 release files

0.5.7

2 release files

0.5.6

2 release files

0.5.5

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page