Skip to main content

AI Sandbox (AI Sandbox)

Overview

An AI Sandbox is an isolated execution environment used to safely run AI-generated code, execute commands, or conduct experiments. The sandbox ensures that AI operations do not impact the host system while providing a controlled testing environment.

Core Value: Safety + Controllability + Repeatability


Why you need an AI sandbox

1. Security risks

Without a sandbox, the AI might:

  • Delete important files
  • Execute malicious commands
  • Access sensitive data
  • Consumes system resources
  • Infect the network environment

2. Typical scenario

ScenarioRiskSandbox Solution
AI generated code executionCode may contain malicious logicExecution in container
AI calls system commandsCommands may damage the systemLimit available commands
AI accesses the networkMay access malicious websitesNetwork isolation/proxy
AI modifies filesMay delete important filesFile system isolation

Type of sandbox

1. Process-level sandbox

Isolate a single process:

┌─────────────────────────────────────────────────────────┐
│ Process Sandbox │
├─────────────────────────────────────────────────────────┤
│ │
│ ┌──────────────┐ ┌──────────────┐ │
│ │ Host system │ │ Sandbox process │ │
│ │ │ │ │ │
│ │ ┌────────┐ │ ──▶ │ ┌────────┐ │ │
│ │ │ Others │ │ │ │ AI code │ │ │
│ │ │ process │ │ │ │ execution │ │ │
│ │ └────────┘ │ │ └────────┘ │ │
│ │ │ │ │ │
│ └──────────────┘ └──────────────┘ │
│ ▲ ▲ │
│ └─────────────────────────┘ │
│ Permission isolation (chroot, namespace) │
│ │
└─────────────────────────────────────────────────────────┘

technology:

  • Linux: chroot, namespace, seccomp
  • macOS: sandbox_exec
  • Windows: Job Objects, Restricted Tokens

2. Container-level sandbox

Isolation using container technology:

┌─────────────────────────────────────────────────────────┐
│ Container Sandbox │
├─────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────────────────────────────────────┐ │
│ │ Host system │ │
│ │ ┌─────────────────────────────────────┐ │ │
│ │ │ Docker/Podman container │ │ │
│ │ │ ┌─────────────────────────────┐ │ │ │
│ │ │ │ AI execution environment │ │ │ │
│ │ │ │ - Independent file system │ │ │ │
│ │ │ │ - Standalone network stack │ │ │ │
│ │ │ │ - Resource limit │ │ │ │
│ │ │ └─────────────────────────────┘ │ │ │
│ │ └─────────────────────────────────────┘ │ │
│ └─────────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────┘

technology:

  • Docker
  • Podman
  • Kubernetes (Pod)
  • gVisor (user space kernel)

3. Virtual machine-level sandbox

Complete virtualization isolation:

┌─────────────────────────────────────────────────────────┐
│ Virtual Machine Sandbox │
├─────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────────────────────────────────────┐ │
│ │ Host operating system │ │
│ │ ┌─────────────────────────────────────┐ │ │
│ │ │ Hypervisor (KVM/VMware) │ │ │
│ │ │ ┌─────────────────────────────┐ │ │ │
│ │ │ │ Virtual machine operating system │ │ │ │
│ │ │ │ ┌─────────────────────┐ │ │ │ │
│ │ │ │ │ AI execution environment │ │ │ │ │
│ │ │ │ │ - Complete Isolation │ │ │ │ │
│ │ │ │ │ - independent kernel │ │ │ │ │
│ │ │ │ │ - Hardware Virtualization │ │ │ │ │
│ │ │ │ └─────────────────────┘ │ │ │ │
│ │ │ └─────────────────────────────┘ │ │ │
│ │ └─────────────────────────────────────┘ │ │
│ └─────────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────┘

technology:

  • KVM / QEMU
  • VMware
  • VirtualBox
  • Firecracker (micro virtual machine)

4. Web Sandbox

Execute JavaScript on the browser/server side:

┌─────────────────────────────────────────────────────────┐
│ Web Sandbox │
├─────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────────────────────────────────────┐ │
│ │ Browser/Server │ │
│ │ ┌─────────────────────────────────────┐ │ │
│ │ │ iframe / Web Worker │ │ │
│ │ │ ┌─────────────────────────────┐ │ │ │
│ │ │ │ AI generated JavaScript │ │ │ │
│ │ │ │ - SOP Limitations │ │ │ │
│ │ │ │ - CSP Strategy │ │ │ │
│ │ │ │ - Memory isolation │ │ │ │
│ │ │ └─────────────────────────────┘ │ │ │
│ │ └─────────────────────────────────────┘ │ │
│ └─────────────────────────────────────────────┘ │
│ │
└─────────────────────────────────────────────────────────┘

technology:

  • iframe + sandbox attribute
  • Web Workers
  • Service Workers
  • QuickJS (embedded JS engine)

Mainstream AI sandbox solution

1. E2B

A sandbox designed specifically for AI code execution:

# Install E2B
pip install e2b

# Usage example
from e2b import Sandbox

sandbox = Sandbox()
result = sandbox.run_code("print('Hello from AI!')")

Features:

  • Designed specifically for LLM
  • Pre-installed commonly used tools
  • Supports multiple programming languages
  • API is simple and easy to use

2. Docker Exec

Use Docker directly as a sandbox:

#Run container execution code
docker run --rm -v $(pwd):/workspace python:3.12 \
python /workspace/script.py

# Limit resources
docker run --rm \
--memory="512m" \
--cpus="1.0" \
--network=none \
python:3.12 python script.py

3. Firecracker

Micro virtual machine used by AWS Lambda:

{
"boot_source": {
"kernel_image_path": "vmlinux.bin"
},
"drives": [
{
"drive_id": "rootfs",
"path_on_host": "rootfs.ext4",
"is_root_device": true,
"is_read_only": false
}
],
"machine_config": {
"vcpu_count": 1,
"mem_size_mib": 512
}
}

4. WebAssembly (WASM)

Safely execute in your browser:

// QuickJS WASM sandbox
import { getQuickJS } from 'quickjs-emscripten';

const { evalCode } = await getQuickJS();

//Execute code in an isolated environment
const result = evalCode(`
const sum = (a, b) => a + b;
sum(1, 2);
`);

Sandbox usage in AI tools

Claude Code CLI

Claude Code uses a system-wide sandbox:

// Safely execute commands
const result = await Bash({
command: "npm test",
options: {
timeout: 30000,
cwd: workspaceDir,
env: { ...process.env, NODE_ENV: 'test' }
}
});

Safety Measures:

  • Command timeout limit
  • working directory restrictions
  • Environment variable filtering
  • File access control

Cursor IDE

Cursor uses a container to execute code:

  • Each Tab runs in an independent environment
  • File system access requires user authorization
  • Network requests configurable

GitHub Codespaces

Complete cloud development environment as sandbox:

User code → Codespaces container → Isolated execution environment

Resource limits

network isolation

Build your own AI sandbox

Basic solution: Python subprocess

import subprocess
import tempfile
import os

def execute_in_sandbox(code: str, timeout: int = 30):
"""Execute code in temporary directory"""
with tempfile.TemporaryDirectory() as tmpdir:
#Write code file
code_file = os.path.join(tmpdir, 'script.py')
with open(code_file, 'w') as f:
f.write(code)

# Execute code (with timeout)
result = subprocess.run(
['python', code_file],
cwd=tmpdir,
timeout=timeout,
capture_output=True,
text=True
)

return result.stdout, result.stderr, result.returncode

Intermediate solution: Docker

import docker

def execute_in_docker(code: str, language: str = 'python'):
"""Execute code in a Docker container"""
client = docker.from_env()

# Run container
container = client.containers.run(
f'{language}:3.12-slim',
command=['python', '-c', code],
mem_limit='512m',
cpu_quota=100000,
network_disabled=True,
detach=True
)

# Wait for execution to complete
result = container.wait()
logs = container.logs()

# cleanup
container.remove()

return logs.decode('utf-8')

Advanced solution: gVisor

# Use gVisor to run the container
docker run --runtime=runsc --rm python:3.12 python -c "print('Hello')"

Best practices for sandboxing

1. Resource limitations

ResourcesRecommended LimitationsReasons
CPU1-2 coresPrevent CPU hogs
Memory512MB-2GBPrevent memory exhaustion
Disk1GBLimit storage usage
NetworkDisable or proxyPrevent malicious access
Time30-60 secondsPrevent infinite loops

2. File system isolation

  • Use temporary file system
  • Disable access to host directory
  • Provide virtual file system

3. Network isolation

  • Network disabled by default
  • Use whitelist when needed
  • Log all network requests

4. Logging and monitoring

  • Record all operations
  • Monitor resource usage
  • Abnormal behavior alerts

5. Cleaning mechanism

  • Automatically clean up after execution
  • Clean up residue regularly
  • Resource recovery

Comparison of sandbox solutions

SolutionIsolation levelPerformanceComplexityApplicable scenarios
Process LevelLowHighLowSimple Script
ContainerMediumHighMediumGeneral Scenario
Virtual MachineHighMediumHighHigh Security Requirements
Web WASMMediumMediumLowBrowser Environment
E2BMediumHighLowFast integration

Reference resources

Open source projects

document


Document updated: December 2025