Microsoft Execution Containers hit GA: sandbox any AI agent
Policy-enforced isolation now ships in Codex and Copilot CLI, Claude Code next — the default way to run untrusted agents. Plus a free self-hosted agent on HN.

Copy markdown
A deny-by-default sandbox for AI agents
Microsoft Execution Containers (MXC) are now generally available on Windows 11: policy-enforced boundaries that cap which files, network destinations and tools an agent can reach, enforced at runtime. It's open-source and cross-platform (Windows, macOS, Linux) — one JSON policy, a TypeScript SDK (@microsoft/mxc-sdk), and backends from lightweight process containers up to Hyperlight microVMs. Everything defaults to deny; you open only what the task needs.
You can wrap Codex and Copilot CLI with it today
OpenAI Codex, GitHub Copilot, Replit, LM Studio, NVIDIA OpenShell and Unsloth already support MXC, with Anthropic Claude Code, Perplexity, Raycast and Manus listed as coming. In Copilot's sandbox mode a single command confines file access to your working directory, temp and user profile with outbound-only networking — a real way to run an untrusted coding agent without handing it the whole machine.
Build this weekend: your own agent on Cloudflare's free tier
Talorys, trending on Hacker News, stands up a private single-user assistant — chat, memory, tasks, notes and recurring reminders — entirely inside your own Cloudflare account via `npx create-talorys@latest`. It runs GLM-4.7-Flash on Workers AI with a React/Vite UI and a SQLite Durable Object, no external server; when the daily free AI quota runs out, the non-AI features keep working.