Best sandbox for smolagents in 2026
smolagents says only remote execution isolates LLM code robustly; the best remote sandbox is a whole Linux machine, not a snippet runner.
Runtime gives a smolagents agent a Firecracker microVM with its own kernel,
pip and sudo, through four functions that smolagents' @tool wraps as
they are. The agent can install a package in one step, write a module in
the next and run the tests in a third, and the machine remembers all of it.
Forty thousand ninety-second agent runs a month, each busy for 15
CPU-seconds, cost $34.17 on Runtime against
$165.60 on E2B, $237.96 on Modal
and $193.20 on Blaxel, at rates checked
23 September to 2 October 2026.
Which executors does smolagents support?
A CodeAgent hands the Python it writes to an executor chosen by
executor_type. In smolagents 1.26.0, read from its source on
1 October 2026, the accepted values are:
executor_type |
Where the snippet runs | Isolation |
|---|---|---|
local (default) |
Your process, in smolagents' AST-walking interpreter | None beyond the import allow-list |
docker |
A container on your machine | The host's kernel, shared |
e2b |
An E2B sandbox | Firecracker microVM |
modal |
A Modal sandbox | gVisor, a shared kernel |
blaxel |
A Blaxel sandbox | Lightweight VMs |
| Runtime tools | A Runtime microVM, through tool calls | Firecracker microVM, its own kernel |
The secure code execution guide says "no local python sandbox can ever be completely secure", and that "the only way to run LLM-generated code with truly robust security isolation is to use remote execution options".
Snippet runner or machine: which does your agent need?
The remote executors run one Python snippet at a time and send back its
output, which suits a CodeAgent doing arithmetic and data wrangling. An
agent that works on software needs more than that between steps:
- State that outlasts a snippet. Files written in step two are there in step nine, and so is a server started in step four.
- Other languages and tools. The same
runtime_execrunsnpm test,go buildorsqlite3. - Packages on demand.
pip installworks inside the sandbox, with network access you can narrow to PyPI's hosts. - A time limit you set. Each command takes the timeout you give it, and
the sandbox's lease ends where
timeout_secondssays.
Runtime suits a ToolCallingAgent driving a machine; for a CodeAgent, the
code it writes can call the same tools.
What do smolagents runs cost on each executor?
Forty thousand runs a month, each ninety seconds on a 2 vCPU, 4 GiB sandbox and busy for 15 CPU-seconds, at each provider's published rates:
| Provider | Isolation | A month of runs | Runtime costs less by |
|---|---|---|---|
| Runtime | Firecracker microVM | $34.17 | |
| E2B | Firecracker microVM | $165.60 | 79% |
| Modal | gVisor, a shared kernel | $237.96 | 86% |
| Blaxel | Lightweight VMs | $193.20 | 82% |
A run on Runtime, recorded 1 October 2026
Pythonfrom smolagents import InferenceClientModel, ToolCallingAgent, toolfrom withruntime import Sandboxfrom withruntime.tools import sandbox_toolswith Sandbox.create(timeout_seconds=900, on_lease_end="stop") as sbx: agent = ToolCallingAgent(tools=[tool(f) for f in sandbox_tools(sbx)], model=InferenceClientModel(), max_steps=15) print(agent.run("How many CPUs and how much memory does the sandbox have?"))We ran the same ToolCallingAgent loop from smolagents 1.26.0 with a scripted
Model subclass in place of the inference client, so the tool call was fixed
and smolagents executed it against a live sandbox:
textStep 1 Calling tool: 'runtime_exec' nproc && free -m Observations: {'exit_code': 0, 'stdout': '2\n3939 MiB\n', ...}Step 2 Calling tool: 'final_answer' doneThe default size, two vCPUs and 4 GiB, less what the kernel keeps. Testing the tools before paying for a model, and running the whole agent inside the sandbox, are in smolagents in a sandbox.
When might another sandbox fit better?
- A drop-in
executor_type. If you want to keep aCodeAgentexactly as it is and change one argument, the built-ine2b,modalandblaxelexecutors do that; Runtime plugs in as tools.
Sources
Checked 1 October 2026.
- smolagents: Secure code execution: the quotes on local and remote execution
- smolagents on PyPI: version 1.26.0,
whose
CodeAgentsource lists theexecutor_typevalues - Each provider's published rates, checked 23 September to 2 October 2026, as the pricing guide lists them
- The recorded run: Runtime's Python SDK with smolagents 1.26.0 on Python 3.12, against production on 1 October 2026