원클릭으로
isol8
Securely execute untrusted Python, Node.js, Bun, Deno, and Bash code in sandboxed Docker containers.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Securely execute untrusted Python, Node.js, Bun, Deno, and Bash code in sandboxed Docker containers.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Securely execute untrusted Python, Node.js, Bun, Deno, Bash, and AI agent code in sandboxed Docker containers.
Process all linked issues from a GitHub project and implement them as separate PRs. Use when the user provides a GitHub project URL (github.com/owner/repo/projects/N or github.com/orgs/NAME/projects/N) and wants to implement all issues in that project. Each issue becomes its own PR. Handles dependencies using cascading PRs where dependent issues branch off their dependency's PR branch.
Write and revamp product documentation to a high editorial standard using Mintlify, with strong information architecture, precise titles/descriptions, parameter-level clarity, cross-linking, and maintainable examples. Use when creating new docs pages, refactoring existing docs, improving docs structure/navigation, or standardizing docs quality across a repository.
Implement plans based on GitHub issue URLs. Fetches issue details and comments, analyzes requirements, creates implementation plans, validates bugs, implements fixes with commits, and creates PRs with proper labeling. Use when the user provides a GitHub issue URL and wants to implement the feature or fix the bug described in that issue.
| name | isol8 |
| description | Securely execute untrusted Python, Node.js, Bun, Deno, and Bash code in sandboxed Docker containers. |
Isol8 is a secure execution engine for running untrusted code inside Docker containers with strict resource limits, network controls, and output sanitization. Use this skill when you need to execute code, scripts, or system commands in a safe, isolated environment.
For full documentation, see the isol8 docs. This file is a quick-reference for AI agents — it covers the most common operations and links to detailed docs for everything else.
| Command | Purpose | Full Docs |
|---|---|---|
isol8 run [file] | Execute code in an isolated container | CLI: run |
isol8 setup | Build Docker images, optionally bake in packages | CLI: setup |
isol8 cleanup | Remove orphaned isol8 containers (optionally images with --images) | CLI: cleanup |
isol8 serve | Start HTTP server for remote execution (downloads binary on first use) | CLI: serve |
isol8 config | Display resolved configuration | CLI: config |
isol8 run)--eval flag (inline code, defaults to python runtime)--runtime)python runtime)Extension mapping: .py → python, .js/.mjs/.cjs → node, .ts → bun, .mts → deno, .sh → bash
Remote source input: use --url, --github, or --gist (requires remoteCode.enabled=true in config). Add --hash for SHA-256 verification.
isol8 run)| Flag | Default | Description |
|---|---|---|
-e, --eval <code> | — | Execute inline code |
-r, --runtime <name> | auto-detect | Force: python, node, bun, deno, bash |
--no-stream | false | Disable real-time output streaming |
--persistent | false | Keep container alive between runs |
--persist | false | Keep container after execution for debugging |
--debug | false | Enable internal debug logging |
--install <package> | — | Install package before execution (repeatable). If --net is omitted, CLI auto-uses filtered and allowlists default runtime registries |
--url <url> | — | Fetch source code from URL |
--github <owner/repo/ref/path> | — | GitHub shorthand for raw source |
--gist <gistId/file.ext> | — | Gist shorthand for raw source |
--hash <sha256> | — | Verify SHA-256 hash for fetched code |
--allow-insecure-code-url | false | Allow insecure http:// code URLs for this request |
--net <mode> | none | Network: none, host, filtered (explicit value is never overridden) |
--timeout <ms> | 30000 | Execution timeout |
--memory <limit> | 512m | Memory limit |
--secret <KEY=VALUE> | — | Secret env var, value masked in output (repeatable) |
--stdin <data> | — | Pipe data to stdin |
For the complete flag reference (20 flags total), see CLI: run.
# Python inline
isol8 run -e "print('Hello!')" --runtime python
# Run a file (runtime auto-detected)
isol8 run script.py
# With package installation
isol8 run -e "import numpy; print(numpy.__version__)" --runtime python --install numpy
# Pipe via stdin
echo "console.log(42)" | isol8 run --runtime node
# Secrets (masked as *** in output)
isol8 run -e "import os; print(os.environ['KEY'])" --runtime python --secret KEY=sk-1234
# Remote execution
isol8 run script.py --host http://server:3000 --key my-api-key
# Cleanup orphaned containers
isol8 cleanup # Interactive (prompts for confirmation)
isol8 cleanup --force # Skip confirmation
isol8 cleanup --images --force # Also remove isol8 images
For full library documentation, see Library Overview.
import { DockerIsol8 } from "isol8";
const isol8 = new DockerIsol8({
mode: "ephemeral", // or "persistent"
network: "none", // or "host" or "filtered"
memoryLimit: "512m",
cpuLimit: 1.0,
timeoutMs: 30000,
secrets: {}, // values masked in output
persist: false, // keep container after execution for debugging
debug: false, // enable internal debug logging
});
await isol8.start();
const result = await isol8.execute({
codeUrl: "https://raw.githubusercontent.com/user/repo/main/script.py",
codeHash: "<sha256>",
runtime: "python",
installPackages: ["numpy"], // optional
});
console.log(result.stdout); // captured output
console.log(result.exitCode); // 0 = success
console.log(result.durationMs);
await isol8.stop();
Full options reference: Execution Options
import { RemoteIsol8 } from "isol8";
const isol8 = new RemoteIsol8(
{ host: "http://localhost:3000", apiKey: "secret" },
{ network: "none" }
);
await isol8.start();
const result = await isol8.execute({ code: "print(1)", runtime: "python" });
await isol8.stop();
for await (const event of isol8.executeStream({
code: 'for i in range(5): print(i)',
runtime: "python",
})) {
if (event.type === "stdout") process.stdout.write(event.data);
if (event.type === "exit") console.log("Exit code:", event.data);
}
Full streaming docs: Streaming
await isol8.putFile("/sandbox/data.csv", "col1,col2\n1,2");
const buf = await isol8.getFile("/sandbox/output.txt");
Full file I/O docs: File I/O
Full endpoint reference: Server Endpoints
| Method | Path | Auth | Description |
|---|---|---|---|
GET | /health | No | Health check |
POST | /execute | Yes | Execute code, return result |
POST | /execute/stream | Yes | Execute code, SSE stream |
POST | /file | Yes | Upload file (base64) |
GET | /file | Yes | Download file (base64) |
DELETE | /session/:id | Yes | Destroy persistent session |
POST | /cleanup | Yes | Trigger remote cleanup for sessions/containers (images optional) |
Config is loaded from (first found): ./isol8.config.json or ~/.isol8/config.json. Partial configs are deep-merged with defaults.
Full configuration reference: Configuration
| Layer | Default |
|---|---|
| Filesystem | Read-only root, /sandbox tmpfs 512MB (exec allowed), /tmp tmpfs 256MB (noexec) |
| User isolation | Non-root sandbox user (uid 100), processes killed between pool reuses |
| Processes | PID limit 64, no-new-privileges |
| Resources | 1 CPU, 512MB memory, 30s timeout |
| Network | Disabled (none), iptables enforcement in filtered mode |
| Output | Truncated at 1MB, secrets masked |
| Seccomp | strict default profile (blocks mount, swap, ptrace, etc.); standalone server binaries use embedded fallback when profile files are missing |
Container Filesystem:
/sandbox (512MB): Working directory, packages installed here, execution allowed for .so files/tmp (256MB): Temporary files, no execution allowed for securityFull security model: Security
isol8 setup to check.--timeout. Process is killed on timeout.--memory.--sandbox-size (default 512MB) or --tmp-size (default 256MB).--sandbox-size large enough for installation (512MB+ recommended)..ts files running with Bun instead of Deno: .ts defaults to Bun. Use --runtime deno or .mts extension.isol8 serve --update to force a fresh download. Use isol8 serve --debug to see detailed server logs. For listen port selection, precedence is --port > ISOL8_PORT > PORT > 3000; if the port is busy, serve can prompt for another port or auto-pick an available one.strict/custom mode, execution fails if profile loading fails. Verify security.customProfilePath for custom mode.