01Controlled network access for external API calls and package installations.
02Utilizes Linux namespaces, cgroups, and seccomp-bpf for robust isolation.
03Secure Python code execution within isolated sandboxes using NsJail.
04Configurable sandbox environment with custom dependencies and system mounts.
050 GitHub stars
06Strict resource limits (memory, CPU, output size) and filesystem isolation.