🏜️ A sandbox that runs user-supplied JavaScript/TypeScript scripts.
-
Updated
Jun 17, 2023 - TypeScript
🏜️ A sandbox that runs user-supplied JavaScript/TypeScript scripts.
Safely execute untrusted code with ESM syntax support, dynamic injection of ESM modules from URL or plain JS code, and granular access control based on whitelisting for each JS object.
Want to see how something like Internet Chemotherapy works without bricking your own vms? This is a jail to reduce the python runtime from doing bad things on the host when running untrusted code. Nerf what you do not need 👾 + 🐛 ⚽ 🏈 🐳
Safely run untrusted repos (fake-interview malware, infostealers, RATs) in a locked-down, ephemeral container. No host secrets reachable, network denied by default, every egress attempt blocked and logged. Use meguard run <repo_url>, not a risky git clone plus npm install.
Embeddable, process-isolated JavaScript runtime for untrusted and AI-generated code.
A framework-agnostic browser plugin runtime: run untrusted code in an isolated WASM backend (QuickJS built in), expose a host-defined API, and render UI in sandboxed iframes
The Artemis Java Test Sandbox: the second Java implementation of the SCORE (Secure COder Remote Execution) framework. Sandboxes student submissions via policy-based static analysis (ArchUnit/WALA) and runtime instrumentation (AspectJ/Byte Buddy) over file, network, command, thread and JVM access, with deadline-aware hidden tests and clear feedback.
Send code. Wait a bit. Get response!
Gives an AI agent (or any untrusted code) a full, hardened sandbox VM that can reach the internet but nothing on your network.
A dramatic cybersecurity awareness demonstration that simulates a system breach by revealing user information and system details.
Run python code in a sandbox
🔍 Eliminate data until revealed with Ghost Protocol, a privacy system that ensures security through absence, not secrecy.
CLI programs sandboxing solution for GNU/Linux, used in Overtest LMS
Sandbox for running untrusted JavaScript in the browser.
Secure sandbox execution for JS/TS services inside hardware-isolated microVMs
No-admin Windows process sandbox library for Rust with AppContainer and Windows Sandbox API backends
A compute primitive for safely running untrusted code in Firecracker microVMs - Rust core, TypeScript SDK.
Run untrusted code in Firecracker microVMs on your own hardware. Go daemon + CLI, with Go/Python/TypeScript SDKs generated from one OpenAPI spec.
aiohttp API that runs untrusted code inside hardened, ephemeral containers with no capabilities, read-only root, CPU/memory/PID/disk usage caps and a hard wall-clock timeout.
To associate your repository with the untrusted-code topic, visit your repo's landing page and select "manage topics."