# microsoft/mxc > Cross-platform sandboxed execution system for running untrusted code (model output, plugins, tools) on Windows, Linux, and macOS with configurable filesystem, network, and UI policies. - Magnitude: 4.8 out of 10 — Breakout - Stars: 1,509 total · +5 stars measured 2026-10-08, 10:59–11:46 UTC, ≈ 27 by evening - Star trust: star growth looks organic - Category: Security · Language: Rust · License: MIT · Created: 2026-02-06 · Last push: 2026-10-08 - GitHub: https://github.com/microsoft/mxc · Page: https://gitnova.dev/en/r/microsoft/mxc ## Useful for - Run untrusted model or plugin code inside an isolated container - Restrict a workload's filesystem and network access via JSON policy - Debug sandbox access-denied failures with --debug or --audit mode ## Why it’s here - Star-counter measurements on 2026-10-08 (UTC), 10:59–11:46: 1504 → 1509 stars (+5). This is the change over that interval. - Estimated end-of-day forecast: about +27 stars, using observed gains and the previous day. - Before this, the repository barely got any stars — about 3 per day. - GitHub Trending Rust today: #4, +106 stars. - Recent forks include notable developers: @timrogers (355 followers), @ppenna (275 followers). ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 97 - Issues and pull requests: 1,288 - Watchers: 8 - Average over the last week: 17 per day - Usual pace: 3 per day - Stars in the last hour (measured): 5 - Latest release: v1.0.0 (2026-10-07) ## Stars per day, last 30 days (oldest → newest, today is partial) 2026-09-09 … 2026-10-08: 9, 0, 11, 4, 1, 0, 1, 3, 3, 3, 6, 4, 0, 3, 7, 4, 4, 4, 4, 0, 3, 4, 1, 1, 2, 3, 3, 4, 77, 5 ## Spotted in now - GitHub Trending Rust today: #4, +106 stars ## Similar by description 1. **pydantic/monty** — 2.5 · Steady · AI agents · Rust · +10 stars measured 2026-10-08, 00:04–11:50 UTC, ≈ 19 by evening A minimal, secure Python interpreter written in Rust for running code generated by AI models without containers or VMs. It isolates filesystem, network and environment variables, and enforces memory, time and recursion limits. Full card: https://gitnova.dev/en/r/pydantic/monty.md 2. **NVIDIA/OpenShell** — 3.3 · Cooling · AI agents · Rust · +127 stars measured 2026-10-08, 00:04–11:48 UTC, ≈ 237 by evening A safe, private runtime for autonomous AI agents: isolated sandbox containers governed by declarative YAML policies restricting filesystem, network, and process access. Manages credential injection for agents like Claude, Codex, OpenCode,… Full card: https://gitnova.dev/en/r/NVIDIA/OpenShell.md 3. **google/gvisor** — 2.6 · Steady · Security · Go · +12 stars measured 2026-10-08, 00:04–11:59 UTC, ≈ 23 by evening gVisor is an application kernel implementing a Linux-like interface in userspace in Go. It isolates containers from the host kernel, reducing container escape risk when running untrusted code. Full card: https://gitnova.dev/en/r/google/gvisor.md 4. **google/ax** — 2.6 · Cooling · AI agents · Go · +51 stars measured 2026-10-08, 00:05–11:50 UTC, ≈ 92 by evening A declarative orchestrator for running autonomous AI agent workloads in a cluster, using a Kubernetes-like model with Task, Workspace, Gateway, and Model manifests. It sandboxes agents, pre-wires their environment, and restricts network… Full card: https://gitnova.dev/en/r/google/ax.md 5. **stacklok/toolhive** — 1.3 · Steady · AI agents · Go · +0 stars measured 2026-10-08, 10:59–11:55 UTC, ≈ 2 by evening Platform for running and managing MCP servers in isolated containers with access policies, a registry, and a gateway. Lets you securely connect MCP to AI clients locally or on Kubernetes. Full card: https://gitnova.dev/en/r/stacklok/toolhive.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-08 12:00 UTC, updated every 30 minutes.