# Best sandbox for smolagents in 2026 smolagents says only remote execution isolates LLM code robustly; the best remote sandbox is a whole Linux machine, not a snippet runner. **Runtime gives a smolagents agent a Firecracker microVM with its own kernel, `pip` and `sudo`, through four functions that smolagents' `@tool` wraps as they are.** The agent can install a package in one step, write a module in the next and run the tests in a third, and the machine remembers all of it. Forty thousand ninety-second agent runs a month, each busy for 15 CPU-seconds, cost $34.17 on Runtime against $165.60 on E2B, $237.96 on Modal and $193.20 on Blaxel, at rates checked 23 September to 2 October 2026. ## Which executors does smolagents support? A `CodeAgent` hands the Python it writes to an executor chosen by `executor_type`. In smolagents 1.26.0, read from its source on 1 October 2026, the accepted values are: | `executor_type` | Where the snippet runs | Isolation | | ----------------- | ---------------------------------------------------- | ----------------------------------- | | `local` (default) | Your process, in smolagents' AST-walking interpreter | None beyond the import allow-list | | `docker` | A container on your machine | The host's kernel, shared | | `e2b` | An E2B sandbox | Firecracker microVM | | `modal` | A Modal sandbox | gVisor, a shared kernel | | `blaxel` | A Blaxel sandbox | Lightweight VMs | | Runtime tools | A Runtime microVM, through tool calls | Firecracker microVM, its own kernel | The [secure code execution guide](https://huggingface.co/docs/smolagents/tutorials/secure_code_execution) says "no local python sandbox can ever be completely secure", and that "the only way to run LLM-generated code with truly robust security isolation is to use remote execution options". ## Snippet runner or machine: which does your agent need? The remote executors run one Python snippet at a time and send back its output, which suits a `CodeAgent` doing arithmetic and data wrangling. An agent that works on software needs more than that between steps: - **State that outlasts a snippet.** Files written in step two are there in step nine, and so is a server started in step four. - **Other languages and tools.** The same `runtime_exec` runs `npm test`, `go build` or `sqlite3`. - **Packages on demand.** `pip install` works inside the sandbox, with network access you can narrow to PyPI's hosts. - **A time limit you set.** Each command takes the timeout you give it, and the sandbox's lease ends where `timeout_seconds` says. Runtime suits a `ToolCallingAgent` driving a machine; for a `CodeAgent`, the code it writes can call the same tools. ## What do smolagents runs cost on each executor? Forty thousand runs a month, each ninety seconds on a 2 vCPU, 4 GiB sandbox and busy for 15 CPU-seconds, at each provider's published rates: | Provider | Isolation | A month of runs | Runtime costs less by | | -------- | ----------------------- | -------------------------------- | --------------------------------- | | Runtime | Firecracker microVM | $34.17 | | | E2B | Firecracker microVM | $165.60 | 79% | | Modal | gVisor, a shared kernel | $237.96 | 86% | | Blaxel | Lightweight VMs | $193.20 | 82% | ## A run on Runtime, recorded 1 October 2026 ```python check from smolagents import InferenceClientModel, ToolCallingAgent, tool from withruntime import Sandbox from withruntime.tools import sandbox_tools with Sandbox.create(timeout_seconds=900, on_lease_end="stop") as sbx: agent = ToolCallingAgent(tools=[tool(f) for f in sandbox_tools(sbx)], model=InferenceClientModel(), max_steps=15) print(agent.run("How many CPUs and how much memory does the sandbox have?")) ``` We ran the same `ToolCallingAgent` loop from smolagents 1.26.0 with a scripted `Model` subclass in place of the inference client, so the tool call was fixed and smolagents executed it against a live sandbox: ```text Step 1 Calling tool: 'runtime_exec' nproc && free -m Observations: {'exit_code': 0, 'stdout': '2\n3939 MiB\n', ...} Step 2 Calling tool: 'final_answer' done ``` The default size, two vCPUs and 4 GiB, less what the kernel keeps. Testing the tools before paying for a model, and running the whole agent inside the sandbox, are in [smolagents in a sandbox](/integrations/smolagents). ## When might another sandbox fit better? - **A drop-in `executor_type`.** If you want to keep a `CodeAgent` exactly as it is and change one argument, the built-in `e2b`, `modal` and `blaxel` executors do that; Runtime plugs in as tools. ## Sources Checked 1 October 2026. - [smolagents: Secure code execution](https://huggingface.co/docs/smolagents/tutorials/secure_code_execution): the quotes on local and remote execution - [smolagents on PyPI](https://pypi.org/project/smolagents/): version 1.26.0, whose `CodeAgent` source lists the `executor_type` values - Each provider's published rates, checked 23 September to 2 October 2026, as the [pricing guide](/docs/pricing) lists them - The recorded run: Runtime's Python SDK with smolagents 1.26.0 on Python 3.12, against production on 1 October 2026