← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

MXC: Cross-Platform Sandboxed Code Execution System for Untrusted Code

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Runs untrusted code on Windows, Linux, macOS
  • Offers multiple containment backends
  • Provides Rust, .NET, and Node SDKs
  • Supports policy-driven sandboxing

Introduction to MXC

MXC is a sandboxed code execution system developed for running untrusted code, including model output, plugins, and tools. It supports Windows, Linux, and macOS, providing a consistent approach to isolating potentially malicious or unstable code within applications.

Unified Containment Model and Backends

The system features a unified containment model that abstracts various underlying containment technologies. These range from OS-native process sandboxes like ProcessContainer, Windows Sandbox, LXC, Bubblewrap, and Seatbelt, to full virtual machines such as MicroVM (Nanvix), Hyperlight, IsolationSession, and WSLC. This allows applications to select the appropriate level of isolation based on their needs and the operating system.

Policy-Driven Sandboxing and SDKs

MXC implements policy-driven sandboxing, enabling granular control over filesystem access (read-only, read-write, denied paths), network activity (proxy support, outbound controls), and UI interactions (clipboard, display, GUI access). Developers can integrate MXC into their applications using provided SDKs for Rust, .NET, and Node, which offer versioned APIs for both one-shot and state-aware execution of containers. The system also includes diagnostic tools to troubleshoot access-denied failures within a container.

Integration and Workload Execution

Applications integrate MXC as an SDK dependency. The application specifies the container type, containment rules, and the workload command. MXC then validates the request, selects the appropriate backend, and launches the workload within the isolated container. For scenarios where SDK embedding is not feasible, platform-specific executor binaries are available, accepting JSON container-creation requests based on a stable schema.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~5 min · 3 stories · Oct 09

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

MXC is a new sandboxed code execution system designed to run untrusted code, such as model output, plugins, and tools, across Windows, Linux, and macOS. It provides a unified containment model with various backends, from OS-native process sandboxes to full virtual machines, and offers SDKs for Rust, .NET, and Node, allowing developers to integrate secure execution environments into their applications.