weft-microsandbox
Microsandbox runner plugin for Weft.
This extension runs disposable command and one-shot provider_cli agent tasks
inside Microsandbox microVM sandboxes. It is intended for probably-hostile tools,
MCP servers, and skills that need a harder process and filesystem boundary than
the host runner.
The runner name is microsandbox.
Install with:
uv add 'weft[microsandbox]'
The current Microsandbox SDK supports Linux x86_64/aarch64 and macOS Apple
Silicon. The SDK is Apache-2.0 licensed. A working local Microsandbox runtime
is required for real execution; weft spec validate --preflight --load-runner
checks the local runtime gate explicitly.
Tool Mode
{
"spec": {
"type": "command",
"process_target": "python",
"args": ["-c", "print('hello')"],
"runner": {
"name": "microsandbox",
"options": {
"image": "python:3.12-alpine",
"mode": "tool",
"network": "none",
"workspace_mode": "none"
}
}
}
}
Agent Mode
{
"spec": {
"type": "agent",
"persistent": false,
"agent": {
"runtime": "provider_cli",
"conversation_scope": "per_message",
"runtime_config": {
"provider": "codex"
}
},
"runner": {
"name": "microsandbox",
"options": {
"image": "ghcr.io/acme/codex-provider:latest",
"mode": "agent",
"executable": "codex",
"network": "allow",
"workspace_mode": "none"
}
}
}
}
runner.options.executable is the executable inside the guest image. It is not
resolved on the host.
Runner Options
image: required OCI image.mode: optional; derived fromspec.typeastoolfor command tasks andagentfor agent tasks.executable: required for agent mode; guest-local provider CLI command.network:noneby default, orallow.workspace_mode:noneby default, orcopy,mount-read-only, ormount-read-write.mounts: explicit host mounts. Entries default to read-only.cwd: guest working directory. Required for workspace modes.sandbox_name_prefix: optional runtime name prefix.
Security Defaults
networkdefaults tonone.workspace_modedefaults tonone.- host environment variables are not forwarded unless they are explicit in
spec.env. - persistent and interactive tasks are rejected.
Current Limitations
Memory, CPU, and file-descriptor limits are passed to the Microsandbox SDK, but
the runner does not yet map SDK OOM or metrics evidence to
RunnerOutcome(status="limit"). A guest killed by the runtime for memory
pressure may currently surface as a generic execution error.
This runner is a process, VM, and filesystem boundary. It is not a semantic defense against prompt injection or malicious output.
Release files for weft-microsandbox 0.5.6
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| weft_microsandbox-0.5.6.tar.gz | 12.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| weft_microsandbox-0.5.6-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 27.9 kB
Release files / weft_microsandbox-0.5.6.tar.gz
| Download URL | weft_microsandbox-0.5.6.tar.gz |
|---|---|
| Size | 12.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
84bf7fed41fb69af6e8fd4866863dc02d6b69e23fa3d00c4b16e49064fbf5253
|
|
BLAKE2b-256 checksum How to use checksums |
b2d7ac0667db9574e2ca22600faf71e023807fa6d0aa54c819afc0bfb7501e53
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / weft_microsandbox-0.5.6-py3-none-any.whl
| Download URL | weft_microsandbox-0.5.6-py3-none-any.whl |
|---|---|
| Size | 15.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8491f2102404ac38b3d071fdfc174191a1e42a45bc1d70db198667f8bc0277d2
|
|
BLAKE2b-256 checksum How to use checksums |
dd080c52ee11df79f9032be1ff8d91a3b8a8df2e80fd77f2ace3fdd3ea3b5eb6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.11.11 {"installer":{"name":"uv","version":"0.11.11","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|