Runtime

Best sandbox for smolagents in 2026

smolagents says only remote execution isolates LLM code robustly; the best remote sandbox is a whole Linux machine, not a snippet runner.

Runtime gives a smolagents agent a Firecracker microVM with its own kernel, pip and sudo, through four functions that smolagents' @tool wraps as they are. The agent can install a package in one step, write a module in the next and run the tests in a third, and the machine remembers all of it. Forty thousand ninety-second agent runs a month, each busy for 15 CPU-seconds, cost $34.17 on Runtime against $165.60 on E2B, $237.96 on Modal and $193.20 on Blaxel, at rates checked 23 September to 2 October 2026.

Which executors does smolagents support?

A CodeAgent hands the Python it writes to an executor chosen by executor_type. In smolagents 1.26.0, read from its source on 1 October 2026, the accepted values are:

executor_type Where the snippet runs Isolation
local (default) Your process, in smolagents' AST-walking interpreter None beyond the import allow-list
docker A container on your machine The host's kernel, shared
e2b An E2B sandbox Firecracker microVM
modal A Modal sandbox gVisor, a shared kernel
blaxel A Blaxel sandbox Lightweight VMs
Runtime tools A Runtime microVM, through tool calls Firecracker microVM, its own kernel

The secure code execution guide says "no local python sandbox can ever be completely secure", and that "the only way to run LLM-generated code with truly robust security isolation is to use remote execution options".

Snippet runner or machine: which does your agent need?

The remote executors run one Python snippet at a time and send back its output, which suits a CodeAgent doing arithmetic and data wrangling. An agent that works on software needs more than that between steps:

  • State that outlasts a snippet. Files written in step two are there in step nine, and so is a server started in step four.
  • Other languages and tools. The same runtime_exec runs npm test, go build or sqlite3.
  • Packages on demand. pip install works inside the sandbox, with network access you can narrow to PyPI's hosts.
  • A time limit you set. Each command takes the timeout you give it, and the sandbox's lease ends where timeout_seconds says.

Runtime suits a ToolCallingAgent driving a machine; for a CodeAgent, the code it writes can call the same tools.

What do smolagents runs cost on each executor?

Forty thousand runs a month, each ninety seconds on a 2 vCPU, 4 GiB sandbox and busy for 15 CPU-seconds, at each provider's published rates:

Provider Isolation A month of runs Runtime costs less by
Runtime Firecracker microVM $34.17
E2B Firecracker microVM $165.60 79%
Modal gVisor, a shared kernel $237.96 86%
Blaxel Lightweight VMs $193.20 82%

A run on Runtime, recorded 1 October 2026

Pythonfrom smolagents import InferenceClientModel, ToolCallingAgent, toolfrom withruntime import Sandboxfrom withruntime.tools import sandbox_toolswith Sandbox.create(timeout_seconds=900, on_lease_end="stop") as sbx:    agent = ToolCallingAgent(tools=[tool(f) for f in sandbox_tools(sbx)], model=InferenceClientModel(), max_steps=15)    print(agent.run("How many CPUs and how much memory does the sandbox have?"))

We ran the same ToolCallingAgent loop from smolagents 1.26.0 with a scripted Model subclass in place of the inference client, so the tool call was fixed and smolagents executed it against a live sandbox:

textStep 1  Calling tool: 'runtime_exec'  nproc && free -m        Observations: {'exit_code': 0, 'stdout': '2\n3939 MiB\n', ...}Step 2  Calling tool: 'final_answer'  done

The default size, two vCPUs and 4 GiB, less what the kernel keeps. Testing the tools before paying for a model, and running the whole agent inside the sandbox, are in smolagents in a sandbox.

When might another sandbox fit better?

  • A drop-in executor_type. If you want to keep a CodeAgent exactly as it is and change one argument, the built-in e2b, modal and blaxel executors do that; Runtime plugs in as tools.

Sources

Checked 1 October 2026.

  • smolagents: Secure code execution: the quotes on local and remote execution
  • smolagents on PyPI: version 1.26.0, whose CodeAgent source lists the executor_type values
  • Each provider's published rates, checked 23 September to 2 October 2026, as the pricing guide lists them
  • The recorded run: Runtime's Python SDK with smolagents 1.26.0 on Python 3.12, against production on 1 October 2026

Your first 100 hoursare on us.

  • No credit card
  • Eight sandboxes at once, 2 vCPU and 4 GiB each
  • Then prepaid credit from $10, no plan fee
Claim 100 hours free