What it contains
Pre-release code-acting agent runtime executing generated JavaScript handlers inside hardware-isolated Hyperlight micro-VMs with explicit host capabilities.
Typical uses
Experiment with bounded data/API/artifact automation while denying ambient shell/filesystem/network access by default.
Why people choose it
Inference: chosen when sandbox isolation is the main architectural requirement and pre-release risk is acceptable.
Last meaningful updateUnknown
Production readinessprototype
Classification
Subject domains
AI agentssandboxingsecure automation
Task categories
AI agentssandboxingsecure automation
Project phases
implementationoperations
Secondary types
CLIsandboxed runtimeMCP client
Select when
- Need hardware-isolated execution for generated code
Do not select when
- Production use
- macOS
- No hardware virtualization
Implementation complexityhigh
Routing heuristic 72.0%
Security boundary clarity
5/5 First-party routing documentation
5/5 Strengths
None documented.
Poor-fit scenarios
- Production use
- macOS
- No hardware virtualization
Limitations
None documented.
README.md
Validate/run JS handlers in micro-VM.
sandbox
README.md
Path-jailed file/domain-scoped HTTP capabilities.
filesHTTP
README.md
PPTX/XLSX/PDF/Markdown/HTML outputs.
artifacts
README.md
Expose approved MCP tools as host modules.
MCP
README.md
pptx/pdf/xlsx/report/data/API/web/MCP guidance.
skills
FrameworksNone documented
RuntimesNode.js 22+, GitHub Copilot SDK
Operating systemsLinux/KVM, Windows/WHP, WSL2/KVM, Azure Linux/MSHV
Installation methodsNone documented
InterfacesNone documented
Required credentialsGitHub/Copilot authentication
External servicesNone documented
Hardwarehardware virtualization
Major dependenciesNone documented
Compatibility notes
None documented.
One-sentence semantic summary
Pre-release code-acting agent runtime executing generated JavaScript handlers inside hardware-isolated Hyperlight micro-VMs with explicit host capabilities.
Capability keywords
micro-VM executionhandler validationdocumentsapproved HTTP/filesMCP
User intent phrases
- Need hardware-isolated execution for generated code
Negative match phrases
- Production use
- macOS
- No hardware virtualization
Differentiators
None documented.
Security considerations
- README says pre-release/not production; avoid auto-approve for untrusted work.
Privacy considerations
None documented.
Uncertainty
Unresolved items
- License not conclusively verified in the inspected first-party material.
Inference notes
None documented.
Repository usage guidance
installation summaryUnknown
basic usage summaryExperiment with bounded data/API/artifact automation while denying ambient shell/filesystem/network access by default.
documented entry pointsNone documented
key configuration filesNone documented
important directoriesNone documented
documentation pathsREADME.md
example pathsNone documented
Relationships
No explicit repository relationships indexed.
Recommended combinations
Not part of a curated combination.
Routing rules
rule_039: Need hardware-isolated execution for generated code P961
Rationale
Pre-release code-acting agent runtime executing generated JavaScript handlers inside hardware-isolated Hyperlight micro-VMs with explicit host capabilities.
Required conditions
None documented.
Preferred
hyperlight-dev/hyperagent
Fallback
None