Asked before it runs
A task is admitted before it starts or wakes. Past the month's hours, or the member's running cap, it stays stopped and says why.
Each muxcode task can run in its own sandbox on Cloudflare. The agent reads, edits and runs checks there, while the model loop, your model keys and every permission decision stay on your Mac.
Pro and Pro+ · One sandbox per task · Runs on Cloudflare
The sandbox never sees a model. muxcode keeps the conversation and decides what may run; the sandbox only carries out the reads, edits and commands it is sent.
A command runs in the light shell when it can, with no network at all. It moves to the container when a program it names is missing. Both see the same workspace.
grep -r TODO src (runs) cat package.json (runs) cargo test (runs) mvn test (runs) Model traffic never reaches the sandbox, and nothing of muxcode's is installed there. It only carries out the reads, edits and commands it is sent.
Only the variables the app sends for the task reach a command. Paths outside the workspace are refused, and every command stops after 30 minutes.
The container reaches the internet through one gateway. It can fetch packages and clone from GitHub; it cannot push, publish or send your code anywhere.
Package registries, crates, Go, Maven and Gradle, Packagist, GitHub and Debian mirrors are on the list. Reads to them go through. A push, a publish or any other host does not.
npm install zod (runs) git fetch (runs) git push (refused) curl paste.example (refused) Authorization and cookie headers are removed from every request, and none is added. A redirect comes back to the container and goes through the same check.
Each request is recorded with its method, host and the rule that answered it.
The repository moves over Git, in both directions. A task works on its own fork, so nothing it does touches your repository until you fetch the result and choose to land it.
After 20 idle minutes the compute stops. The files stay, and the next command wakes it. The container starts only when a command needs it.
The change is committed to a branch on the task's fork, for you to fetch and land. A task stopped for 14 days deletes its files and its fork.
Every request is checked against the workspace key that made it. A sandbox belongs to one task in one workspace, and it can reach nothing else.
The container carries the toolchains muxcode runs a project's tests, linters and type checks with, each pinned to a version and checksum.
The sandbox is included with Pro and Pro+. In a team, each member's own hours join a pool the whole team shares.
A task is admitted before it starts or wakes. Past the month's hours, or the member's running cap, it stays stopped and says why.
At nine-tenths of the month's hours the task says so. At the limit it stops, and its files stay.
Sandbox tasks and triage runs, their activity and checkpoints, show in the workspace console.
Start a task in the sandbox from muxcode, paste one, and change the names to yours.
Run the Go and PHP test suites in the sandbox and fix whatever fails.
Run the full integration suite in the sandbox and tell me which tests are slowest.
Try the Postgres 17 upgrade in the sandbox. Migrate, run the tests, and leave my machine alone.
Upgrade every dependency to its latest major, run the build, and checkpoint only if it is green.
Reproduce the bug from issue 412 in a clean checkout and show me the failing test first.
Install the project from a clean clone and list every package it downloads.
The desktop harness is free. Pro and Pro+ add the cloud sandbox, search by meaning and re-index on push.