# AutoGen code executor alternative: run agent code in a microVM Pass Runtime's sandbox functions to an AutoGen `AssistantAgent` as tools, and the agent's commands run in a remote Firecracker microVM. **On Runtime the agent gets a disposable Linux machine without Docker on your host.** AutoGen's recommended isolation, `DockerCommandLineCodeExecutor`, needs a Docker daemon wherever the agent runs. A Runtime sandbox needs only the `withruntime` package: it is a microVM with its own kernel on servers Runtime operates, ready in 351 ms at the median (24 September 2026), and it bills the CPU the code uses, so a 2 vCPU, 4 GiB sandbox costs $0.03125 an hour while AutoGen waits on the model. autogen-agentchat 0.7.5 was the current PyPI release on 25 September 2026. ## AutoGen's own executors AutoGen 0.7 runs model-written code through a `CodeExecutor`, used by the experimental `CodeExecutorAgent` or by `PythonCodeExecutionTool` on an `AssistantAgent`. These ship in `autogen-ext` 0.7.5: | Executor | Where code runs | Isolation | | -------------------------------- | ----------------------------------------- | ------------------------------------------ | | `LocalCommandLineCodeExecutor` | Your machine | None; AutoGen says "use it with caution" | | `JupyterCodeExecutor` | A Jupyter kernel on your machine | None | | `DockerCommandLineCodeExecutor` | A Docker container | A container sharing the host's kernel | | `DockerJupyterCodeExecutor` | A Jupyter server in Docker | A container sharing the host's kernel | | `ACADynamicSessionsCodeExecutor` | Azure Container Apps dynamic sessions | Azure's session pool; needs an Azure setup | | Runtime tools (this page) | A Runtime Firecracker microVM, over HTTPS | A virtual machine with its own kernel | The executors run code blocks the model writes in its reply. The Runtime tools work the other way: the model calls `runtime_exec` with a shell command, which suits agents that install packages, run tests and edit files. ## Wire it up `AssistantAgent` turns plain Python functions into tools by itself, reading their type hints and docstrings. `sandbox_tools` bound to an `AsyncSandbox` returns coroutines, which fits AutoGen's async runtime. ```bash no-run pip install -U "autogen-agentchat" "autogen-ext[openai]" withruntime ``` ```python check from autogen_agentchat.agents import AssistantAgent from autogen_core.models import ChatCompletionClient from withruntime import AsyncRuntime from withruntime.tools import sandbox_tools async def solve(model_client: ChatCompletionClient, task: str) -> str: async with AsyncRuntime() as runtime: async with await runtime.sandboxes.create(timeout_seconds=900, on_lease_end="stop") as sbx: agent = AssistantAgent( "engineer", model_client=model_client, tools=sandbox_tools(sbx), max_tool_iterations=12, system_message="Work in the Linux sandbox. Check exit codes. Reply TERMINATE when done.", ) result = await agent.run(task=task) return str(result.messages[-1].content) ``` `max_tool_iterations` matters: its default is 1, which lets the agent make one round of tool calls and then answer. Raise it so the agent can run a command, read the error and try again. Any AutoGen model client works, for example `OpenAIChatCompletionClient(model=...)` from `autogen_ext.models.openai`. The four tools, the same in every framework: | Tool | Does | | -------------------- | -------------------------------------------------------- | | `runtime_exec` | Runs a bash command; returns exit code, stdout, stderr | | `runtime_read_file` | Returns a text file; relative paths are under /workspace | | `runtime_write_file` | Creates or replaces a file, making parent directories | | `runtime_list_files` | Lists a directory's entries with type and size | ## A team that shares one machine In a `RoundRobinGroupChat` or `SelectorGroupChat`, give the coder and the tester the tools from the same sandbox. The tester then runs the files the coder wrote, with no copying between containers. Give a reviewer agent no tools at all, so it can read results but never run anything. Each team run can take its own sandbox, and a paid account runs 100 at once to start. ## Contain what the agent can reach Create the sandbox with rules instead of trusting the prompt: ```python check from withruntime import AsyncRuntime from withruntime.tools import sandbox_tools async def analyst_tools(runtime: AsyncRuntime): sbx = await runtime.sandboxes.create( network={"internet": True, "allow": ["pypi.org", "*.pythonhosted.org"]}, timeout_seconds=600, on_lease_end="stop", max_cost_micros=50_000, ) await sbx.exec("pip install pandas", check=True, timeout_ms=180_000) await sbx.network.set(internet=False) # nothing leaves while the agent works return sbx, sandbox_tools(sbx) ``` Call `await sbx.stop()` when the team finishes; the lease stops it anyway after 600 seconds. - The network rules, CPU, memory and cost are enforced on the host. Root inside the sandbox cannot change them ([security](/docs/security)). - `max_cost_micros=50_000` refuses the create if its first lease would cost more than five cents. - Tokens the agent's code needs, such as a GitHub token for a private clone, go in as [secrets](/docs/security#secrets-sandboxes-never-see): the sandbox holds a placeholder, and the host adds the real value only on requests to the hosts you name. - The application's Runtime key can carry a daily spending limit that no key can raise. Past it, creates fail with `spending_limit_reached`. ## AutoGen's status AutoGen's README says the project "is now in maintenance mode" and that "new users should start with Microsoft Agent Framework". AgentChat 0.7.5 stays on PyPI for projects already built on it. The Runtime tools are ordinary typed functions, not an AutoGen plugin, so they move with you to whichever framework takes Python functions as tools ([any other framework](/docs/frameworks#any-other-framework)). ## When to choose which - **Local executor:** your own code, on your own laptop, in a demo. - **Docker executor:** a single trusted host where Docker is already running. - **Azure dynamic sessions:** an Azure shop that wants Python cells only. - **Runtime:** agents open to untrusted input, many agents in parallel, or hosts with no Docker, such as serverless functions. More on the isolation question in [Docker vs a virtual machine](/compare/docker-vs-virtual-machine) and [local Docker vs a cloud sandbox](/compare/local-docker-vs-cloud-sandbox); more on the workload in [a coding agent sandbox](/use-cases/coding-agent-sandbox). New accounts get 50 free sandbox hours, no card: ```bash no-run npx withruntime sandbox run --trial -- python3 -c 'print(6 * 7)' ``` ## Sources - [AutoGen README](https://github.com/microsoft/autogen), maintenance notice and install line, read 25 September 2026 - [AutoGen: Command line code executors](https://microsoft.github.io/autogen/stable/user-guide/core-user-guide/components/command-line-code-executors.html), read 25 September 2026 - [AutoGen AgentChat: Agents](https://microsoft.github.io/autogen/stable/user-guide/agentchat-user-guide/tutorial/agents.html), read 25 September 2026 - [autogen-agentchat on PyPI](https://pypi.org/project/autogen-agentchat/) and [autogen-ext](https://pypi.org/project/autogen-ext/), version 0.7.5; executor classes and the `max_tool_iterations` default read from that release's source on 25 September 2026 Facts on this page were checked on 25 September 2026.