Skip to content
View original post on X: meng shao· 43/100AI score43/100

Unsloth integrates Microsoft's mxc sandbox for Windows AI agent isolation

AISummary

Unsloth has integrated Microsoft's open-source mxc sandboxing system into Windows as an OS-level sandbox for isolating AI agent code execution.

Its High mode provides real operating-system isolation that confines tool calls to specified directories, while its Low mode adds language-level checks that block dangerous commands and shell escapes.

Both modes also strip secret environment variables and enforce resource limits such as 8GB memory and 600-second CPU time.

Post on XView on X
@shao__meng

Unsloth 与 Windows 团队合作,把微软开源的跨平台沙箱系统「mxc」集成为 Windows 上的操作系统级沙箱,用于隔离 AI Agent 的代码执行 @UnslothAI @Windows

mxc (Microsoft eXecution Container) 是什么?
微软开源(MIT 协议)的沙箱化代码执行系统,定位就是隔离“不可信代码:模型输出、插件和工具”。几个关键设计:
· 统一抽象、多后端:应用通过 SDK(Rust / .NET / Node)声明容器类型、隔离规则和工作负载,mxc 负责校验并选择后端启动。Windows 上默认后端是 ProcessContainer,另有 Windows Sandbox、WSL 容器,以及实验性的 Hyperlight(轻量级 microVM)和 Nanvix 等。
· 策略驱动:文件系统(只读/读写/拒绝路径列表)、网络(代理、出站控制、主机过滤)、UI(剪贴板、显示访问)均可细粒度配置。
· 完整生命周期管理:provision → start → execute → stop → deprovision,支持持久化容器,并带调试与审计模式。

Unsloth 的集成方式
Unsloth 按平台各接入了官方沙箱:Windows 用 mxc(Win11 24H2+ 预装)、Linux 用 bubblewrap、macOS 用 Seatbelt。提供两档安全模式:
· Low(软件沙箱):在语言层做字符串、AST、正则检查;拦截危险命令(磁盘、提权、网络、进程类),分析 Python 代码阻断 shell 逃逸(os.system、subprocess)、网络外传、敏感文件读取等。
· High(系统级沙箱):真正的操作系统隔离,工具调用被限制在指定目录内,无法对系统造成实际伤害。

两档模式下都有纵深防御:剥离密钥环境变量、拒读 Studio 凭据文件,以及资源限额(进程数、单文件 100MB、内存 8GB、CPU 时间 600 秒),即使 fork 炸弹也会撞上进程数上限加调用超时。

Unsloth AI@UnslothAI
Windows now has sandboxing! Microsoft released an open-source repo, mxc, for sandboxed code execution. We collaborated with Windows to add mxc OS level sandboxing to Unsloth which adds just <100 ms of overhead. GitHub: https://github.com/unslothai/unsloth Guide: https://unsloth.ai/docs/new/studio/sandboxing-in-unsloth
View quoted post on X

Source: meng shao · x.comPublished · added here